Data Leakage Vulnerability in OpenStack Keystone API by OpenStack
CVE-2019-19687

8.8HIGH

Key Information:

Vendor
Openstack
Status
Vendor
CVE Published:
9 December 2019

Summary

OpenStack Keystone versions 15.0.0 and 16.0.0 are susceptible to a data leakage issue within the credentials API. When the enforce_scope parameter is set to false, any user assigned a role within a project can exploit the /v3/credentials API to list and retrieve the credentials of other users. This issue compromises sensitive information, including those related to Time-based One-Time Passwords (TOTP), leading to potential misuse and unauthorized access to resources. Affected deployments should address this vulnerability to maintain data security and integrity.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.