{"id":"GHSA-8833-qrvm-wc3h","summary":"OpenStack Keystone allows context-dependent attackers to bypass access restrictions","details":"OpenStack Keystone Grizzly before 2013.1, Folsom 2012.1.3 and earlier, and Essex does not properly check if the (1) user, (2) tenant, or (3) domain is enabled when using EC2-style authentication, which allows context-dependent attackers to bypass access restrictions.","aliases":["CVE-2013-0282","PYSEC-2026-652"],"modified":"2026-07-06T08:11:37.211415819Z","published":"2022-05-05T02:48:43Z","database_specific":{"nvd_published_at":"2013-04-12T22:55:00Z","cwe_ids":["CWE-287"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2024-05-09T16:47:05Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2013-0282"},{"type":"WEB","url":"https://github.com/openstack/keystone/commit/7402f5ef994599653bdbb3ed5ff1a2b8c3e72b9f"},{"type":"WEB","url":"https://github.com/openstack/keystone/commit/9572bfc393f66f5ce3b44c0a77a9e29cc0374c6f"},{"type":"WEB","url":"https://github.com/openstack/keystone/commit/f0b4d300db5cc61d4f079f8bce9da8e8bea1081a"},{"type":"WEB","url":"https://bugs.launchpad.net/keystone/+bug/1121494"},{"type":"WEB","url":"https://launchpad.net/keystone/+milestone/2012.2.4"},{"type":"WEB","url":"https://launchpad.net/keystone/grizzly/2013.1"},{"type":"WEB","url":"https://review.openstack.org/#/c/22319"},{"type":"WEB","url":"https://review.openstack.org/#/c/22320"},{"type":"WEB","url":"https://review.openstack.org/#/c/22321"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2013/02/19/3"}],"affected":[{"package":{"name":"keystone","ecosystem":"PyPI","purl":"pkg:pypi/keystone"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"8.0.0a0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-8833-qrvm-wc3h/GHSA-8833-qrvm-wc3h.json"}}],"schema_version":"1.9.0"}