PT-2019-11593 · Red Hat · Python-Novajoin

Published

2019-07-30

·

Updated

2020-09-30

·

CVE-2019-10138

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Red Hat OpenStack Platform python-novajoin plugin versions prior to 1.1.1
Description: A flaw was discovered in the python-novajoin plugin, where the novajoin API lacked sufficient access control. This allowed any keystone authenticated user to generate FreeIPA tokens.
Recommendations: For versions prior to 1.1.1, update to version 1.1.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the novajoin API to minimize the risk of exploitation.

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-10138
GHSA-XF8C-3CGX-FCWM
PYSEC-2019-192
RHSA-2019:1728

Affected Products

Python-Novajoin