5.3

CVE-2018-14432

In the Federation component of OpenStack Keystone before 11.0.4, 12.0.0, and 13.0.0, an authenticated "GET /v3/OS-FEDERATION/projects" request may bypass intended access restrictions on listing projects. An authenticated user may discover projects they have no authority to access, leaking all projects in the deployment and their attributes. Only Keystone with the /v3/OS-FEDERATION endpoint enabled via policy.json is affected.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Debian ≫ Debian Linux Version 9.0
Redhat ≫ Openstack Version 10
Redhat ≫ Openstack Version 12
Redhat ≫ Openstack Version 13
Openstack ≫ Keystone Version < 11.0.4
Openstack ≫ Keystone Version 12.0.0
Openstack ≫ Keystone Version 13.0.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.62% 0.729
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.3 1.6 3.6
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
NIST 3.5 6.8 2.9
AV:N/AC:M/Au:S/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

http://www.openwall.com/lists/oss-security/2018/07/25/2
Patch
Third Party Advisory
Mailing List
http://www.securityfocus.com/bid/104930
Third Party Advisory
VDB Entry
https://access.redhat.com/errata/RHSA-2018:2523
Vendor Advisory
https://access.redhat.com/errata/RHSA-2018:2533
Vendor Advisory
https://access.redhat.com/errata/RHSA-2018:2543
Vendor Advisory
https://www.debian.org/security/2018/dsa-4275
Third Party Advisory