{"id":"CVE-2014-0204","aliases":["GHSA-c4p9-87h3-7vr4","PYSEC-2026-654"],"url":"https://o3.security/vulnerability/CVE-2014-0204","summary":"OpenStack Identity Keystone Improper Privilege Management","details":"OpenStack Identity (Keystone) before 2014.1.1 does not properly handle when a role is assigned to a group that has the same ID as a user, which allows remote authenticated users to gain privileges that are assigned to a group with the same ID.","published":"2014-11-03T23:55:05Z","modified":"2026-07-06T08:11:34.694118050Z","cvss":null,"epss":{"score":0.01397,"percentile":0.71112,"asOf":"2026-09-17"},"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"PyPI","name":"keystone","fixedVersion":"8.0.0a0"}],"fix":null,"references":[{"type":"ADVISORY","url":"http://www.openwall.com/lists/oss-security/2014/05/21/3"},{"type":"ADVISORY","url":"https://bugs.launchpad.net/keystone/+bug/1309228"},{"type":"ADVISORY","url":"https://review.openstack.org/#/c/94396/"},{"type":"ARTICLE","url":"http://www.openwall.com/lists/oss-security/2014/05/21/3"},{"type":"EVIDENCE","url":"https://bugs.launchpad.net/keystone/+bug/1309228"},{"type":"FIX","url":"http://www.openwall.com/lists/oss-security/2014/05/21/3"},{"type":"FIX","url":"https://review.openstack.org/#/c/94396/"},{"type":"REPORT","url":"https://bugs.launchpad.net/keystone/+bug/1309228"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-06T08:11:34.694118050Z"}}