OSSA-2014-015: Keystone user and group id mismatch

OSSA-2014-015: Keystone user and group id mismatch


May 21, 2014




  • Keystone: 2014.1


Michael Stancampiano from IBM reported a vulnerability in Keystone. Someone with write access to the user and group repository (such as the LDAP directory server) may willingly or unwillingly grant additional rights by picking the same IDs for users and groups, resulting in roles assigned to a group being assigned to the affected user even if he is not a member of this group. Only Keystone setups using LDAP for the Identity driver are affected.


  • Michael Stancampiano from IBM (CVE-2014-0204)

Creative Commons Attribution 3.0 License

Except where otherwise noted, this document is licensed under Creative Commons Attribution 3.0 License. See all OpenStack Legal Documents.