PT-2018-15283 · Openstack · Openstack Keystone
Andy Ngo
+1
·
Published
2018-12-17
·
Updated
2024-08-05
·
CVE-2018-20170
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
OpenStack Keystone versions through 14.0.1
Description
The issue allows for user enumeration due to the difference in response times for valid and invalid usernames when making a POST request to the "/v3/auth/tokens" endpoint. The vendor views this as a hardening opportunity rather than a security issue.
Recommendations
For OpenStack Keystone versions through 14.0.1, consider implementing measures to equalize response times for valid and invalid usernames to mitigate the user enumeration risk. As a temporary workaround, restrict access to the "/v3/auth/tokens" endpoint to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openstack Keystone