The LDAP backend in OpenStack Identity (Keystone) Grizzly and Havana, when removing a role on a tenant for a user who does not have that role, adds the role to the user, which allows local users to gain privileges.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Grizzly | Openstack | - (including) | - (including) |
| Havana | Openstack | - (including) | - (including) |
| OpenStack 3 for RHEL 6 | RedHat | openstack-keystone-0:2013.1.4-2.el6ost | * |
| Keystone | Ubuntu | quantal | * |
| Keystone | Ubuntu | raring | * |
| Keystone | Ubuntu | saucy | * |
| Keystone | Ubuntu | upstream | * |