Access Control Vulnerability in OpenStack Keystone Federation Component
CVE-2018-14432
5.3MEDIUM
What is CVE-2018-14432?
In the Federation component of OpenStack Keystone, prior to specific versions, an authenticated 'GET /v3/OS-FEDERATION/projects' request can exploit access controls. This flaw allows authenticated users to list projects they have no rights to access, leading to the unauthorized disclosure of project details and attributes. The vulnerability specifically affects Keystone configurations that have the /v3/OS-FEDERATION endpoint enabled through policy.json.