Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-10138

Опубликовано: 17 янв. 2019
Источник: redhat
CVSS3: 7.1
EPSS Низкий

Описание

A flaw was discovered in the python-novajoin plugin, all versions up to, excluding 1.1.1, for Red Hat OpenStack Platform. The novajoin API lacked sufficient access control, allowing any keystone authenticated user to generate FreeIPA tokens.

A flaw was discovered in the python-novajoin plugin for Red Hat OpenStack Platform. The novajoin API lacked sufficient access control, allowing any keystone authenticated user to generate FreeIPA tokens.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenStack Platform 15 (Stein)python-novajoinNot affected
Red Hat OpenStack Platform 13.0 (Queens)python-novajoinFixedRHSA-2019:172810.07.2019
Red Hat OpenStack Platform 14.0 (Rocky)ansible-role-container-registryFixedRHBA-2019:094430.04.2019
Red Hat OpenStack Platform 14.0 (Rocky)ansible-role-redhat-subscriptionFixedRHBA-2019:094430.04.2019
Red Hat OpenStack Platform 14.0 (Rocky)ansible-role-tripleo-modify-imageFixedRHBA-2019:094430.04.2019
Red Hat OpenStack Platform 14.0 (Rocky)ansible-tripleo-ipsecFixedRHBA-2019:094430.04.2019
Red Hat OpenStack Platform 14.0 (Rocky)openstack-barbicanFixedRHBA-2019:094430.04.2019
Red Hat OpenStack Platform 14.0 (Rocky)openstack-designateFixedRHBA-2019:094430.04.2019
Red Hat OpenStack Platform 14.0 (Rocky)openstack-heat-uiFixedRHBA-2019:094430.04.2019
Red Hat OpenStack Platform 14.0 (Rocky)openstack-kuryr-kubernetesFixedRHBA-2019:094430.04.2019

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-284
https://bugzilla.redhat.com/show_bug.cgi?id=1670573python-novajoin: novajoin API lacks access control

EPSS

Процентиль: 63%
0.00442
Низкий

7.1 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
nvd
больше 6 лет назад

A flaw was discovered in the python-novajoin plugin, all versions up to, excluding 1.1.1, for Red Hat OpenStack Platform. The novajoin API lacked sufficient access control, allowing any keystone authenticated user to generate FreeIPA tokens.

CVSS3: 8.8
github
почти 6 лет назад

Improper Access Control in novajoin

EPSS

Процентиль: 63%
0.00442
Низкий

7.1 High

CVSS3