{"id":"CVE-2014-3476","aliases":["GHSA-274v-r947-v34r","PYSEC-2026-649"],"title":"OpenStack Identity Keystone is vulnerable to Block delegation escalation of privilege","summary":"OpenStack Identity Keystone is vulnerable to Block delegation escalation of privilege","severity":"medium","vendor":"keystone","product":"keystone","ecosystem":"pip","affected":["keystone < 8.0.0a0"],"patched":["keystone 8.0.0a0"],"published":"2022-05-13","updated":"2026-07-06","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-274v-r947-v34r","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2014-3476"},{"url":"https://bugs.launchpad.net/keystone/+bug/1324592"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2014-06/msg00031.html"},{"url":"http://secunia.com/advisories/57886"},{"url":"http://secunia.com/advisories/59547"},{"url":"http://www.openwall.com/lists/oss-security/2014/06/12/3"},{"url":"http://www.securityfocus.com/bid/68026"}],"tags":["osv","pip"],"epss":0.02327,"epssPercentile":0.82596,"ingestedAt":"2026-07-08T18:25:44.163Z","slug":"CVE-2014-3476","body":"## Overview\n\nOpenStack Identity (Keystone) before 2013.2.4, 2014.1 before 2014.1.2, and Juno before Juno-2 does not properly handle chained delegation, which allows remote authenticated users to gain privileges by leveraging a (1) trust or (2) OAuth token with impersonation enabled to create a new token with additional roles.\n\n## Affected packages\n\n- `keystone < 8.0.0a0`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `keystone 8.0.0a0`","depth":"sunlit","depthScore":28,"depthScoreParts":{"impact":27.5,"likelihood":0.5,"exploitation":0,"ransomware":0},"changes":[]}