Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xf8c-3cgx-fcwm

Опубликовано: 12 мар. 2020
Источник: github
Github: Прошло ревью
CVSS4: 8.7
CVSS3: 8.8

Описание

Improper Access Control in novajoin

A flaw was discovered in the python-novajoin plugin, all versions up to, excluding 1.1.1, for Red Hat OpenStack Platform. The novajoin API lacked sufficient access control, allowing any keystone authenticated user to generate FreeIPA tokens.

Пакеты

Наименование

novajoin

pip
Затронутые версииВерсия исправления

<= 1.1.0

1.1.1

EPSS

Процентиль: 63%
0.00442
Низкий

8.7 High

CVSS4

8.8 High

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 7.1
redhat
около 7 лет назад

A flaw was discovered in the python-novajoin plugin, all versions up to, excluding 1.1.1, for Red Hat OpenStack Platform. The novajoin API lacked sufficient access control, allowing any keystone authenticated user to generate FreeIPA tokens.

CVSS3: 8.8
nvd
больше 6 лет назад

A flaw was discovered in the python-novajoin plugin, all versions up to, excluding 1.1.1, for Red Hat OpenStack Platform. The novajoin API lacked sufficient access control, allowing any keystone authenticated user to generate FreeIPA tokens.

EPSS

Процентиль: 63%
0.00442
Низкий

8.7 High

CVSS4

8.8 High

CVSS3

Дефекты

CWE-284