CVE-2019-19687: High severity Openstack Keystone vulnerability
A vulnerability was found in Keystone's list credentials API. Any user with a role on a project is able to list any credentials with the /v3/credentials API when enforcescope is false. Users with a role on a project are able to view any other users' credentials, which could leak sign-on information for Time-based One Time Passwords (TOTP) or othewise. Deployments running keystone with enforcescope set to false are affected. There will be a slight performance impact for the list credentials API once this issue is fixed. Affects: ==15.0.0, ==16.0.0
Other sources
OpenStack Keystone 15.0.0 and 16.0.0 is affected by Data Leakage in the list credentials API. Any user with a role on a project is able to list any credentials with the /v3/credentials API when enforcescope is false. Users with a role on a project are able to view any other users' credentials, which could (for example) leak sign-on information for Time-based One Time Passwords (TOTP). Deployments with enforcescope set to false are affected. (There will be a slight performance impact for the list credentials API once this issue is fixed.)
— Launchpad
OpenStack Keystone 15.0.0 and 16.0.0 is affected by Data Leakage in the list credentials API. Any user with a role on a project is able to list any credentials with the /v3/credentials API when enforcescope is false. Users with a role on a project are able to view any other users' credentials, which could (for example) leak sign-on information for Time-based One Time Passwords (TOTP). Deployments with enforcescope set to false are affected. (There will be a slight performance impact for the list credentials API once this issue is fixed.)
— GitHub
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2019-19687.
Which versions of OpenStack Keystone are affected?
OpenStack Keystone 15.0.0 and 16.0.0 are affected.
What is the severity of CVE-2019-19687?
The severity of CVE-2019-19687 is high (8.8).
How can I fix the vulnerability?
To fix the vulnerability, update to OpenStack Keystone 15.0.1, 16.0.1, or a later version.
Where can I find more information about this vulnerability?
You can find more information about this vulnerability in the references provided: [link1], [link2], [link3].