Access Control Vulnerability in OpenStack Keystone Federation Component
CVE-2018-14432
5.3MEDIUM
Summary
In the Federation component of OpenStack Keystone, prior to specific versions, an authenticated 'GET /v3/OS-FEDERATION/projects' request can exploit access controls. This flaw allows authenticated users to list projects they have no rights to access, leading to the unauthorized disclosure of project details and attributes. The vulnerability specifically affects Keystone configurations that have the /v3/OS-FEDERATION endpoint enabled through policy.json.
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved