An authorization-check flaw was discovered in federation configurations of the OpenStack Identity service (keystone). An authenticated federated user could request permissions to a project and unintentionally be granted all related roles including administrative roles.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| keystone(PyPI) | 9.0.0 | N/A | N/A |
| keystone(PyPI) | 10.0.0 | 10.0.2 | N/A |
| keystone(PyPI) | 11.0.0 | 11.0.1 | N/A |
CVSS Metrics