← Vulnerability feed

Vulnerability record · CVE-2013-4477 · published 2 November 2013

CVE-2013-4477: Openstack grizzly permissions and access controls vulnerability

Openstack · Grizzly

The LDAP backend in OpenStack Identity (Keystone) Grizzly and Havana, when removing a role on a tenant for a user who does not have that role, adds the role to the user, which allows local users to gain privileges.

3.3 CVSS 2.0 Low EPSS 0.45% · top 63.6% CWE-264 · Permissions and access controls
3.3CVSS 2.0 base score
0.45%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
8References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

The LDAP backend in OpenStack Identity (Keystone) Grizzly and Havana, when removing a role on a tenant for a user who does not have that role, adds the role to the user, which allows local users to gain privileges.

AV:L/AC:M/Au:N/C:P/I:P/A:N

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2013-4477 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.6CVE-2013-0335Openstack essex insufficient session expiration vulnerabilityOpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to gain access to a VM in opportunistic circu…EPSS 2.1%7.5CVE-2013-2161Openstack folsom code injection vulnerabilityXML injection vulnerability in account/utils.py in OpenStack Swift Folsom, Grizzly, and Havana allows attackers to trigger invalid or spoofed Swift r…EPSS 1.9%7.1CVE-2013-7130Openstack compute information exposure vulnerabilityThe i_create_images_and_backing (aka create_images_and_backing) method in libvirt driver in OpenStack Compute (Nova) Grizzly, Havana, and Icehouse, w…EPSS 2.4%6.4CVE-2013-4497Openstack havana permissions and access controls vulnerabilityThe XenAPI backend in OpenStack Compute (Nova) Folsom, Grizzly, and Havana before 2013.2 does not properly apply security groups (1) when resizing an…EPSS 1.8%5.0CVE-2013-6419Openstack havana information exposure vulnerabilityInteraction error in OpenStack Nova and Neutron before Havana 2013.2.1 and icehouse-1 does not validate the instance ID of the tenant making a reques…EPSS 1.9%5.0CVE-2013-1664Openstack cinder folsom memory buffer overflow vulnerabilityThe XML libraries for Python 3.4, 3.3, 3.2, 3.1, 2.7, and 2.6, as used in OpenStack Keystone Essex, Folsom, and Grizzly; Compute (Nova) Essex and Fol…EPSS 4.9%4.3CVE-2013-4179Openstack havana memory buffer overflow vulnerabilityThe security group extension in OpenStack Compute (Nova) Grizzly 2013.1.3, Havana before havana-3, and earlier allows remote attackers to cause a den…EPSS 2.7%4.3CVE-2012-5625Openstack folsom information exposure vulnerabilityOpenStack Compute (Nova) Folsom before 2012.2.2 and Grizzly, when using libvirt and LVM backed instances, does not properly clear physical volume (PV…EPSS 2.0%

Source: NIST National Vulnerability Database (record CVE-2013-4477), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.