Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2j23-fwqm-mgwr

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 8.7
CVSS3: 8.8

Описание

OpenStack Keystone Credential Leakage

OpenStack Keystone 15.0.0 and 16.0.0 is affected by Data Leakage in the list credentials API. Any user with a role on a project is able to list any credentials with the /v3/credentials API when enforce_scope is false. Users with a role on a project are able to view any other users' credentials, which could (for example) leak sign-on information for Time-based One Time Passwords (TOTP). Deployments with enforce_scope set to false are affected. (There will be a slight performance impact for the list credentials API once this issue is fixed.)

Пакеты

Наименование

keystone

pip
Затронутые версииВерсия исправления

= 15.0.0

15.0.1

Наименование

keystone

pip
Затронутые версииВерсия исправления

= 16.0.0

16.0.1

EPSS

Процентиль: 73%
0.00766
Низкий

8.7 High

CVSS4

8.8 High

CVSS3

Дефекты

CWE-522

Связанные уязвимости

CVSS3: 8.8
ubuntu
около 6 лет назад

OpenStack Keystone 15.0.0 and 16.0.0 is affected by Data Leakage in the list credentials API. Any user with a role on a project is able to list any credentials with the /v3/credentials API when enforce_scope is false. Users with a role on a project are able to view any other users' credentials, which could (for example) leak sign-on information for Time-based One Time Passwords (TOTP). Deployments with enforce_scope set to false are affected. (There will be a slight performance impact for the list credentials API once this issue is fixed.)

CVSS3: 8.1
redhat
около 6 лет назад

OpenStack Keystone 15.0.0 and 16.0.0 is affected by Data Leakage in the list credentials API. Any user with a role on a project is able to list any credentials with the /v3/credentials API when enforce_scope is false. Users with a role on a project are able to view any other users' credentials, which could (for example) leak sign-on information for Time-based One Time Passwords (TOTP). Deployments with enforce_scope set to false are affected. (There will be a slight performance impact for the list credentials API once this issue is fixed.)

CVSS3: 8.8
nvd
около 6 лет назад

OpenStack Keystone 15.0.0 and 16.0.0 is affected by Data Leakage in the list credentials API. Any user with a role on a project is able to list any credentials with the /v3/credentials API when enforce_scope is false. Users with a role on a project are able to view any other users' credentials, which could (for example) leak sign-on information for Time-based One Time Passwords (TOTP). Deployments with enforce_scope set to false are affected. (There will be a slight performance impact for the list credentials API once this issue is fixed.)

CVSS3: 8.8
debian
около 6 лет назад

OpenStack Keystone 15.0.0 and 16.0.0 is affected by Data Leakage in th ...

EPSS

Процентиль: 73%
0.00766
Низкий

8.7 High

CVSS4

8.8 High

CVSS3

Дефекты

CWE-522