CVE-2019-3683: keystone_json_assignment backend granted access to any project for users in user-project-map.json
The keystone-json-assignment package in SUSE Openstack Cloud 8 before commit d7888c75505465490250c00cc0ef4bb1af662f9f every user listed in the /etc/keystone/user-project-map.json was assigned full "member" role access to every project. This allowed these users to access, modify, create and delete arbitrary resources, contrary to expectations.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-3683?
CVE-2019-3683 is a vulnerability in the keystone-json-assignment package in SUSE Openstack Cloud 8, which allows users listed in the /etc/keystone/user-project-map.json file to have full "member" role access to every project.
How severe is CVE-2019-3683?
CVE-2019-3683 has a severity rating of 8.8 (high).
Which software versions are affected by CVE-2019-3683?
CVE-2019-3683 affects SUSE Openstack Cloud 8 version 8.0, Suse Keystone-json-assignment version up to exclusive 2019-02-18, and Hp Helion Openstack version 8.0.
How can I fix CVE-2019-3683?
To fix CVE-2019-3683, users should update the keystone-json-assignment package to the patched version.
Where can I find more information about CVE-2019-3683?
More information about CVE-2019-3683 can be found in the following references: [Bugzilla](https://bugzilla.suse.com/show_bug.cgi?id=1124864) and [SUSE](https://www.suse.com/security/cve/CVE-2019-3683/).