Data Leakage Vulnerability in OpenStack Keystone API by OpenStack
CVE-2019-19687
8.8HIGH
Summary
OpenStack Keystone versions 15.0.0 and 16.0.0 are susceptible to a data leakage issue within the credentials API. When the enforce_scope parameter is set to false, any user assigned a role within a project can exploit the /v3/credentials API to list and retrieve the credentials of other users. This issue compromises sensitive information, including those related to Time-based One-Time Passwords (TOTP), leading to potential misuse and unauthorized access to resources. Affected deployments should address this vulnerability to maintain data security and integrity.
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved