OAuth1 Access Token Role Assignment Issue in OpenStack Keystone
CVE-2020-12690
What is CVE-2020-12690?
A vulnerability exists in OpenStack Keystone that allows for the silent ignoring of role parameters in OAuth1 access tokens. When an OAuth1 access token is used to request a Keystone token, it inadvertently includes all role assignments associated with the user's project, regardless of the roles intended to be shared. This misconfiguration could potentially grant users escalated access to resources, allowing for operations that should be restricted based on the initial role permissions. Users of OpenStack Keystone are encouraged to update to recommended versions to mitigate this action.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
