CVE-2013-4477: Low severity openstack grizzly vulnerability
Published Nov 2, 2013
·Updated
The LDAP backend in OpenStack Identity (Keystone) Grizzly and Havana, when removing a role on a tenant for a user who does not have that role, adds the role to the user, which allows local users to gain privileges.
Affected Software
3 affected componentsFixes available
pip/keystone<8.0.0a0
8.0.0a0
Openstack Grizzly
Openstack Havana
Remediation
Patch Available
Event History
Nov 2, 2013
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
May 17, 2022
Advisory Published
via GitHub·04:50 AM
Frequently Asked Questions
1
What is the severity of CVE-2013-4477?
CVE-2013-4477 is classified as a medium severity vulnerability that allows local users to gain privileges inadvertently.
2
How do I fix CVE-2013-4477?
To fix CVE-2013-4477, upgrade to OpenStack Keystone version 8.0.0a0 or later.
3
What software versions are affected by CVE-2013-4477?
CVE-2013-4477 affects OpenStack Identity (Keystone) versions Grizzly and Havana.
4
What is the potential impact of CVE-2013-4477?
The potential impact of CVE-2013-4477 is that unauthorized users can gain additional privileges by exploiting the role management feature.
5
Is CVE-2013-4477 specific to OpenStack?
Yes, CVE-2013-4477 is specific to the OpenStack Identity service, affecting its LDAP backend implementation.