NVD
- Id
- 31664
- Name
- CVE-2014-3476
- Description
- OpenStack Identity (Keystone) before 2013.2.4, 2014.1 before 2014.1.2, and Juno before Juno-2 does not properly handle chained delegation, which allows remote authenticated users to gain privileges by leveraging a (1) trust or (2) OAuth token with impersonation enabled to create a new token with additional roles.
- Reject
- CVSS Version
- 2
- CVSS Score
- 6
- Severity
- Medium
- CVSS Base Score
- 6
- CVSS Impact Subscore
- 6.4
- CVSS Exploit Subscore
- 6.8
- CVSS Vector
- (AV:N/AC:M/Au:S/C:P/I:P/A:P)
- Pub Date
- 2017-01-19
- Published
- 2014-06-17
- Modified Date
- 2017-01-06
- Seq
- 2014-3476