High severity8.8NVD Advisory· Published Jan 17, 2020· Updated Jun 17, 2026
CVE-2019-3683
CVE-2019-3683
Description
The keystone-json-assignment package in SUSE Openstack Cloud 8 before commit d7888c75505465490250c00cc0ef4bb1af662f9f every user listed in the /etc/keystone/user-project-map.json was assigned full "member" role access to every project. This allowed these users to access, modify, create and delete arbitrary resources, contrary to expectations.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5- cpe:2.3:a:hp:helion_openstack:8.0:*:*:*:*:*:*:*
- cpe:2.3:a:suse:keystone-json-assignment:*:*:*:*:*:*:*:*Range: <2019-02-18
cpe:2.3:a:suse:openstack_cloud:8.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:suse:openstack_cloud:8.0:*:*:*:*:*:*:*
- (no CPE)range: keystone-json-assignment
- Range: < commit d7888c75505465490250c00cc0ef4bb1af662f9f
Patches
Vulnerability mechanics
References
2- www.suse.com/security/cve/CVE-2019-3683/nvdVendor Advisory
- bugzilla.suse.com/show_bug.cginvdIssue TrackingPermissions Required
News mentions
0No linked articles in our index yet.