PT-2019-15911 · Openstack+1 · Openstack Keystone+1

Daniel Preussker

·

Publicado

2019-12-09

·

Atualizado

2022-05-24

·

CVE-2019-19687

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenStack Keystone versions 15.0.0 through 16.0.0
Description The issue allows any user with a role on a project to list any credentials using the "/v3/credentials" API endpoint when enforce scope is false. This could lead to data leakage, including sign-on information for Time-based One Time Passwords (TOTP), as users with a role on a project can view any other users' credentials. Deployments with enforce scope set to false are affected.
Recommendations For OpenStack Keystone versions 15.0.0 through 16.0.0, consider setting enforce scope to true to mitigate the risk of data leakage. As a temporary workaround, restrict access to the "/v3/credentials" API endpoint to minimize the risk of exploitation.

Exploit

Correção

Insufficiently Protected Credentials

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-19687
GHSA-2J23-FWQM-MGWR
PYSEC-2019-29
RHSA-2019:4358
USN-4262-1

Produtos afetados

Openstack Keystone
Ubuntu