PT-2019-11593 · Red Hat · Python-Novajoin
Published
2019-07-30
·
Updated
2020-09-30
·
CVE-2019-10138
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Red Hat OpenStack Platform python-novajoin plugin versions prior to 1.1.1
Description:
A flaw was discovered in the python-novajoin plugin, where the novajoin API lacked sufficient access control. This allowed any keystone authenticated user to generate FreeIPA tokens.
Recommendations:
For versions prior to 1.1.1, update to version 1.1.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the novajoin API to minimize the risk of exploitation.
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Python-Novajoin