Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:11246
HistoryJan 15, 2019 - 8:59 a.m.

Authorization Bypass

2019-01-1508:59:08
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
4

0.003 Low

EPSS

Percentile

71.4%

openstack-keystone is vulnerable to authorization bypass attacks. The vulnerability exists as OpenStack Keystone Grizzly before 2013.1, Folsom 2012.1.3 and earlier, and Essex does not properly check if the (1) user, (2) tenant, or (3) domain is enabled when using EC2-style authentication, which allows context-dependent attackers to bypass access restrictions.