← Vulnerability feed

Vulnerability record · CVE-2019-3683 · published 17 January 2020

CVE-2019-3683: Suse openstack cloud incorrect permission assignment vulnerability

Suse · Openstack Cloud

The keystone-json-assignment package in SUSE Openstack Cloud 8 before commit d7888c75505465490250c00cc0ef4bb1af662f9f every user listed in the /etc/keystone/user-project-map.json was assigned full "member" role access to every project. This allowed these users to access, modify, create and delete arbitrary resources, contrary to expectations.

8.8 CVSS 3.1 High EPSS 0.94% · top 40.8% CWE-732 · Incorrect permission assignment
8.8CVSS 3.1 base score, v2 6.5
0.94%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

The keystone-json-assignment package in SUSE Openstack Cloud 8 before commit d7888c75505465490250c00cc0ef4bb1af662f9f every user listed in the /etc/keystone/user-project-map.json was assigned full "member" role access to every project. This allowed these users to access, modify, create and delete arbitrary resources, contrary to expectations.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://bugzilla.suse.com/show_bug.cgi?id=1124864 Issue TrackingPermissions Required
https://www.suse.com/security/cve/CVE-2019-3683/ Vendor Advisory
https://bugzilla.suse.com/show_bug.cgi?id=1124864 Issue TrackingPermissions Required

Track CVE-2019-3683 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2016-3427Oracle Java SE JMX Improper Access Control VulnerabilityCVE-2016-3427 is an unspecified vulnerability in Oracle Java SE 6u113, 7u99, 8u77, Java SE Embedded 8u77, and JRockit R28.3.9, reached through vector…KEVEPSS 92%analysed7.8CVE-2026-31431Linux kernel algif_aead in-place crypto operation flawThe Linux kernel's algif_aead AF_ALG AEAD interface operated in-place on buffers that come from different mappings, a flaw the fix resolves by revert…KEVEPSS 3.4%analysed5.5CVE-2016-3718ImageMagick HTTP/FTP coders allow server-side request forgery via crafted imageImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 mishandles the HTTP and FTP coders, letting a crafted image trigger server-side request forgery. A…KEVEPSS 77%analysed5.5CVE-2016-3715ImageMagick EPHEMERAL coder allows arbitrary file deletionThe EPHEMERAL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 lets a crafted image cause deletion of arbitrary files. This is part of the…KEVEPSS 75%analysed9.8CVE-2017-18017Linux kernel xt_TCPMSS use-after-free in tcpmss_mangle_packetThe tcpmss_mangle_packet function in net/netfilter/xt_TCPMSS.c in the Linux kernel before 4.11 and 4.9.x before 4.9.36 contains a use-after-free that…EPSS 53%analysed9.8CVE-2016-2324Suse linux enterprise debuginfo memory buffer overflow vulnerabilityInteger overflow in Git before 2.7.4 allows remote attackers to execute arbitrary code via a (1) long filename or (2) many nested trees, which trigge…EPSS 18%9.8CVE-2016-2315Suse linux enterprise debuginfo memory buffer overflow vulnerabilityrevision.c in git before 2.7.4 uses an incorrect integer data type, which allows remote attackers to execute arbitrary code via a (1) long filename o…EPSS 17%8.8CVE-2016-3710Debian linux memory buffer overflow vulnerabilityThe VGA module in QEMU improperly performs bounds checking on banked access to video memory, which allows local guest OS administrators to execute ar…EPSS 0.92%

Source: NIST National Vulnerability Database (record CVE-2019-3683), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.