Lucene search

K
redhatRedHatRHSA-2014:0113
HistoryJan 30, 2014 - 12:00 a.m.

(RHSA-2014:0113) Moderate: openstack-keystone security update

2014-01-3000:00:00
access.redhat.com
16

0.0004 Low

EPSS

Percentile

5.1%

The openstack-keystone packages provide keystone, a Python implementation
of the OpenStack Identity service API, which provides Identity, Token,
Catalog, and Policy services.

A flaw was discovered in the way the LDAP backend in keystone handled the
removal of a role. A user could unintentionally be granted a role if the
role being removed had not been previously granted to that user. Note that
only OpenStack Identity setups using an LDAP backend were affected.
(CVE-2013-4477)

All openstack-keystone users are advised to upgrade to these updated
packages, which contain a backported patch to correct this issue.