PT-2018-12509 · Openstack · Openstack Keystone

Kristi Nikolla

·

Published

2018-07-31

·

Updated

2021-08-04

·

CVE-2018-14432

CVSS v3.1

5.3

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenStack Keystone versions prior to 11.0.4 OpenStack Keystone versions prior to 12.0.0 OpenStack Keystone versions prior to 13.0.0
Description The issue allows an authenticated user to bypass access restrictions on listing projects via a "GET /v3/OS-FEDERATION/projects" request, potentially leaking all projects in the deployment and their attributes. This affects Keystone instances with the /v3/OS-FEDERATION endpoint enabled.
Recommendations For versions prior to 11.0.4, update to version 11.0.4 or later. For versions prior to 12.0.0, update to version 12.0.0 or later. For versions prior to 13.0.0, update to version 13.0.0 or later.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-14432
DSA-4275-1
RHSA-2018:2523
RHSA-2018:2533
RHSA-2018:2543
SUSE-SU-2018:2576-1
SUSE-SU-2018:2761-1

Affected Products

Openstack Keystone