---
id: CVE-2013-4477
aliases:
  - GHSA-f889-wfwm-6p7m
  - PYSEC-2026-831
title: OpenStack Identity Keystone Privilege Escalation vulnerability
summary: OpenStack Identity Keystone Privilege Escalation vulnerability
severity: low
vendor: keystone
product: keystone
ecosystem: pip
affected:
  - keystone < 8.0.0a0
patched:
  - keystone 8.0.0a0
published: '2022-05-17'
updated: '2026-07-07'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-f889-wfwm-6p7m'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2013-4477'
  - url: >-
      https://github.com/openstack/keystone/commit/b17e7bec768bd53d3977352486378698a3db3cfa
  - url: >-
      https://github.com/openstack/keystone/commit/c6800ca1ac984c879e75826df6694d6199444ea0
  - url: 'https://bugs.launchpad.net/keystone/+bug/1242855'
  - url: 'https://github.com/openstack/keystone'
  - url: 'http://rhn.redhat.com/errata/RHSA-2014-0113.html'
  - url: 'http://www.openwall.com/lists/oss-security/2013/10/30/6'
  - url: 'http://www.ubuntu.com/usn/USN-2034-1'
tags:
  - osv
  - pip
epss: 0.00447
epssPercentile: 0.38286
ingestedAt: '2026-07-08T18:25:48.836Z'
---

## Overview

The LDAP backend in OpenStack Identity (Keystone) Grizzly and Havana, when removing a role on a tenant for a user who does not have that role, adds the role to the user, which allows local users to gain privileges.

## Affected packages

- `keystone < 8.0.0a0`

## Remediation

Upgrade to a patched release:

- `keystone 8.0.0a0`
