---
id: CVE-2017-2673
aliases:
  - PYSEC-2018-152
  - GHSA-j36m-hv43-7w7m
title: >-
  An authorization-check flaw was discovered in federation configurations of the
  OpenStack Identity service (keystone). An authenticated fe…
summary: >-
  An authorization-check flaw was discovered in federation configurations of the
  OpenStack Identity service (keystone). An authenticated federated user could
  request permissions to a project and unintentionally be granted all related
  roles…
severity: high
cvss: 7.2
cvssVector: 'CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'
vendor: keystone
product: keystone
ecosystem: pip
affected:
  - 'keystone >= 11.0.0, < 11.0.1'
patched:
  - keystone 11.0.1
published: '2018-07-19'
updated: '2026-07-13'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/PYSEC-2018-152'
references:
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2673'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2673'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2673'
  - url: 'https://bugs.launchpad.net/keystone/+bug/1677723'
  - url: 'https://bugs.launchpad.net/keystone/+bug/1677723'
  - url: 'https://bugs.launchpad.net/keystone/+bug/1677723'
  - url: 'http://seclists.org/oss-sec/2017/q2/125'
  - url: 'http://seclists.org/oss-sec/2017/q2/125'
  - url: 'http://seclists.org/oss-sec/2017/q2/125'
  - url: 'https://access.redhat.com/errata/RHSA-2017:1597'
  - url: 'https://access.redhat.com/errata/RHSA-2017:1461'
  - url: 'http://www.securityfocus.com/bid/98032'
  - url: 'http://www.securityfocus.com/bid/98032'
tags:
  - osv
  - pip
epss: 0.02124
epssPercentile: 0.81099
ingestedAt: '2026-07-13T18:58:05.707Z'
---

## Overview

An authorization-check flaw was discovered in federation configurations of the OpenStack Identity service (keystone). An authenticated federated user could request permissions to a project and unintentionally be granted all related roles including administrative roles.

## Affected packages

- `keystone >= 11.0.0, < 11.0.1`

## Remediation

Upgrade to a patched release:

- `keystone 11.0.1`
