{"id":"CVE-2017-2673","aliases":["PYSEC-2018-152","GHSA-j36m-hv43-7w7m"],"title":"An authorization-check flaw was discovered in federation configurations of the OpenStack Identity service (keystone). An authenticated fe…","summary":"An authorization-check flaw was discovered in federation configurations of the OpenStack Identity service (keystone). An authenticated federated user could request permissions to a project and unintentionally be granted all related roles…","severity":"high","cvss":7.2,"cvssVector":"CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","vendor":"keystone","product":"keystone","ecosystem":"pip","affected":["keystone >= 11.0.0, < 11.0.1"],"patched":["keystone 11.0.1"],"published":"2018-07-19","updated":"2026-07-13","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/PYSEC-2018-152","references":[{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2673"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2673"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2673"},{"url":"https://bugs.launchpad.net/keystone/+bug/1677723"},{"url":"https://bugs.launchpad.net/keystone/+bug/1677723"},{"url":"https://bugs.launchpad.net/keystone/+bug/1677723"},{"url":"http://seclists.org/oss-sec/2017/q2/125"},{"url":"http://seclists.org/oss-sec/2017/q2/125"},{"url":"http://seclists.org/oss-sec/2017/q2/125"},{"url":"https://access.redhat.com/errata/RHSA-2017:1597"},{"url":"https://access.redhat.com/errata/RHSA-2017:1461"},{"url":"http://www.securityfocus.com/bid/98032"},{"url":"http://www.securityfocus.com/bid/98032"}],"tags":["osv","pip"],"epss":0.01874,"epssPercentile":0.78163,"ingestedAt":"2026-07-13T18:58:05.707Z","slug":"CVE-2017-2673","body":"## Overview\n\nAn authorization-check flaw was discovered in federation configurations of the OpenStack Identity service (keystone). An authenticated federated user could request permissions to a project and unintentionally be granted all related roles including administrative roles.\n\n## Affected packages\n\n- `keystone >= 11.0.0, < 11.0.1`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `keystone 11.0.1`","depth":"twilight","depthScore":40,"depthScoreParts":{"impact":39.6,"likelihood":0.4,"exploitation":0,"ransomware":0},"changes":[]}