PT-2021-21972 · Openstack+1 · Openstack Keystone+1

Samuel De Medeiros Queiroz

·

Published

2021-08-06

·

Updated

2024-05-03

·

CVE-2021-38155

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: OpenStack Keystone versions 10.x through 16.x before 16.0.2 OpenStack Keystone versions 17.x before 17.0.1 OpenStack Keystone versions 18.x before 18.0.1 OpenStack Keystone versions 19.x before 19.0.1
Description: The issue allows information disclosure during account locking, related to PCI DSS features. By guessing the name of an account and failing to authenticate multiple times, any unauthenticated actor could confirm the account exists and obtain the account's corresponding UUID. This information might be leveraged for other unrelated attacks. All deployments enabling security compliance.lockout failure attempts are affected.
Recommendations: For OpenStack Keystone versions 10.x through 16.x before 16.0.2, update to version 16.0.2 or later. For OpenStack Keystone versions 17.x before 17.0.1, update to version 17.0.1 or later. For OpenStack Keystone versions 18.x before 18.0.1, update to version 18.0.1 or later. For OpenStack Keystone versions 19.x before 19.0.1, update to version 19.0.1 or later. As a temporary workaround, consider disabling the security compliance.lockout failure attempts feature until a patch is available.

Exploit

Fix

Improper Restriction of Excessive Authentication Attempts

Weakness Enumeration

Related Identifiers

ALT-PU-2023-6877
ALT-PU-2024-7169
CVE-2021-38155
DLA-3714-1
GHSA-4225-97PR-RR52
SUSE-SU-2022:1654-1
SUSE-SU-2022:1729-1

Affected Products

Alt Linux
Openstack Keystone