PT-2019-15911 · Openstack+1 · Openstack Keystone+1
Daniel Preussker
·
Published
2019-12-09
·
Updated
2022-05-24
·
CVE-2019-19687
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
OpenStack Keystone versions 15.0.0 through 16.0.0
Description
The issue allows any user with a role on a project to list any credentials using the "/v3/credentials" API endpoint when
enforce scope is false. This could lead to data leakage, including sign-on information for Time-based One Time Passwords (TOTP), as users with a role on a project can view any other users' credentials. Deployments with enforce scope set to false are affected.Recommendations
For OpenStack Keystone versions 15.0.0 through 16.0.0, consider setting
enforce scope to true to mitigate the risk of data leakage. As a temporary workaround, restrict access to the "/v3/credentials" API endpoint to minimize the risk of exploitation.Exploit
Fix
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openstack Keystone
Ubuntu