Data Leakage Vulnerability in OpenStack Keystone API by OpenStack
CVE-2019-19687
What is CVE-2019-19687?
OpenStack Keystone versions 15.0.0 and 16.0.0 are susceptible to a data leakage issue within the credentials API. When the enforce_scope parameter is set to false, any user assigned a role within a project can exploit the /v3/credentials API to list and retrieve the credentials of other users. This issue compromises sensitive information, including those related to Time-based One-Time Passwords (TOTP), leading to potential misuse and unauthorized access to resources. Affected deployments should address this vulnerability to maintain data security and integrity.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
