CVE-2017-2673: Red Hat Openstack
High severity, CVSS 7.2. EPSS: 2.1% chance of exploitation in the next 30 days.
An authorization-check flaw was discovered in federation configurations of the OpenStack Identity service (keystone). An authenticated federated user could request permissions to a project and unintentionally be granted all related roles including administrative roles.
Affected products
- Red Hat Openstack: version 9 only; version 10 only
Published 2018-07-19. Last modified 2026-06-17.