Access Control Vulnerability in OpenStack Keystone Federation Component
CVE-2018-14432

5.3MEDIUM

Key Information:

Vendor
Debian
Vendor
CVE Published:
31 July 2018

Summary

In the Federation component of OpenStack Keystone, prior to specific versions, an authenticated 'GET /v3/OS-FEDERATION/projects' request can exploit access controls. This flaw allows authenticated users to list projects they have no rights to access, leading to the unauthorized disclosure of project details and attributes. The vulnerability specifically affects Keystone configurations that have the /v3/OS-FEDERATION endpoint enabled through policy.json.

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.