CVE-2017-2673High· 7.2▾ TwilightAn authorization-check flaw was discovered in federation configurations of the OpenStack Identity service (keystone). An authenticated federated user could request permissions to a project and unintentionally be granted all related roles…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 39.6 · likelihood 0.4 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 13.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
2.1%
2.1% → 2.1%
An authorization-check flaw was discovered in federation configurations of the OpenStack Identity service (keystone). An authenticated federated user could request permissions to a project and unintentionally be granted all related roles including administrative roles.
keystone >= 11.0.0, < 11.0.1Upgrade to a patched release:
keystone 11.0.1Connected by shared product, vendor, weakness, or advisory.
CVE-2012-3542High· 7.5OpenStack Keystone Allows Remote User Account Creation
CVE-2015-7546High· 7.5OpenStack Identity Keystone and keystonemiddleware Insufficiently Protected Credentials
CVE-2013-1865NoneOpenStack Keystone Folsom (2012.2) does not properly perform revocation checks for Keystone PKI tokens when done through a server, which …
CVE-2012-4457MediumOpenStack Keystone Token authorization for a user in a disabled tenant is allowed
CVE-2026-44394Medium· 6.0OpenStack Keystone's federated token rescoping mechanism doesn't propagate the original token's expiry to the newly issued token
CVE-2026-43000Medium· 6.0OpenStack Keystone has an Incorrect Authorization issue