Description
OpenStack Keystone 15.0.0 and 16.0.0 is affected by Data Leakage in the list credentials API. Any user with a role on a project is able to list any credentials with the /v3/credentials API when enforce_scope is false. Users with a role on a project are able to view any other users' credentials, which could (for example) leak sign-on information for Time-based One Time Passwords (TOTP). Deployments with enforce_scope set to false are affected. (There will be a slight performance impact for the list credentials API once this issue is fixed.)
Published: 2019-12-09
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2019-0072 OpenStack Keystone 15.0.0 and 16.0.0 is affected by Data Leakage in the list credentials API. Any user with a role on a project is able to list any credentials with the /v3/credentials API when enforce_scope is false. Users with a role on a project are able to view any other users' credentials, which could (for example) leak sign-on information for Time-based One Time Passwords (TOTP). Deployments with enforce_scope set to false are affected. (There will be a slight performance impact for the list credentials API once this issue is fixed.)
Github GHSA Github GHSA GHSA-2j23-fwqm-mgwr OpenStack Keystone Credential Leakage
Ubuntu USN Ubuntu USN USN-4262-1 OpenStack Keystone vulnerability
History

No history.

Subscriptions

Openstack Keystone
Redhat Openstack
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-05T02:25:12.373Z

Reserved: 2019-12-09T00:00:00.000Z

Link: CVE-2019-19687

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-12-09T18:15:09.827

Modified: 2024-11-21T04:35:11.607

Link: CVE-2019-19687

cve-icon Redhat

Severity : Important

Publid Date: 2019-12-04T00:00:00Z

Links: CVE-2019-19687 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses