PT-2018-15283 · Openstack · Openstack Keystone

Andy Ngo

+1

·

Published

2018-12-17

·

Updated

2024-08-05

·

CVE-2018-20170

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenStack Keystone versions through 14.0.1
Description The issue allows for user enumeration due to the difference in response times for valid and invalid usernames when making a POST request to the "/v3/auth/tokens" endpoint. The vendor views this as a hardening opportunity rather than a security issue.
Recommendations For OpenStack Keystone versions through 14.0.1, consider implementing measures to equalize response times for valid and invalid usernames to mitigate the user enumeration risk. As a temporary workaround, restrict access to the "/v3/auth/tokens" endpoint to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2018-20170
PYSEC-2018-9

Affected Products

Openstack Keystone