PT-2021-21972 · Openstack+1 · Openstack Keystone+1
Samuel De Medeiros Queiroz
·
Published
2021-08-06
·
Updated
2024-05-03
·
CVE-2021-38155
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
OpenStack Keystone versions 10.x through 16.x before 16.0.2
OpenStack Keystone versions 17.x before 17.0.1
OpenStack Keystone versions 18.x before 18.0.1
OpenStack Keystone versions 19.x before 19.0.1
Description:
The issue allows information disclosure during account locking, related to PCI DSS features. By guessing the name of an account and failing to authenticate multiple times, any unauthenticated actor could confirm the account exists and obtain the account's corresponding UUID. This information might be leveraged for other unrelated attacks. All deployments enabling
security compliance.lockout failure attempts are affected.Recommendations:
For OpenStack Keystone versions 10.x through 16.x before 16.0.2, update to version 16.0.2 or later.
For OpenStack Keystone versions 17.x before 17.0.1, update to version 17.0.1 or later.
For OpenStack Keystone versions 18.x before 18.0.1, update to version 18.0.1 or later.
For OpenStack Keystone versions 19.x before 19.0.1, update to version 19.0.1 or later.
As a temporary workaround, consider disabling the
security compliance.lockout failure attempts feature until a patch is available.Exploit
Fix
Improper Restriction of Excessive Authentication Attempts
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Openstack Keystone