CVSS v3
7.2
HIGH
EPSS Score
2.1 %
exploit probability, as of 2026-09-25
CISA KEV
No
known exploited
Exploitation
—
SSVC status
Description
An authorization-check flaw was discovered in federation configurations of the OpenStack Identity service (keystone). An authenticated federated user could request permissions to a project and unintentionally be granted all related roles including administrative roles.
Technical details
- Published
- 2018-07-19
Frequently asked questions
What is CVE-2017-2673?
An authorization-check flaw was discovered in federation configurations of the OpenStack Identity service (keystone). An authenticated federated user could request permissions to a project and unintentionally be granted all related roles including administrative roles.
Is CVE-2017-2673 actively exploited?
Active exploitation of CVE-2017-2673 has not been confirmed. Its EPSS score was 2.1% on 2026-09-25, the estimated probability of exploitation in the next 30 days.
What is the CVSS score for CVE-2017-2673?
CVE-2017-2673 has a CVSS v3 base score of 7.2 (HIGH severity).
Is CVE-2017-2673 affecting your environment?
Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.
No credit card required · 500 free checks/month · Free API key
Other 2017 vulnerabilities worth triaging
Ranked by exploit probability (EPSS).