Insufficiently protected credentials in OpenStack Keystone - CVE-2019-19687
Published: December 20, 2019
Vulnerability identifier: #VU23776
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-19687
CWE-ID: CWE-522
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to list any credentials.
The vulnerability exists due to data leakage in the list credentials API. A remote user with a role on a project can list any credentials with the "/v3/credentials" API when "enforce_scope" is false.
Affected software
OpenStack Keystone
Red Hat OpenStack for IBM Power
Red Hat OpenStack
keystone (Ubuntu package)
Red Hat OpenStack for IBM Power
Red Hat OpenStack
keystone (Ubuntu package)
How to mitigate CVE-2019-19687
Install updates from vendor's website.
OpenStack Keystone - update to 16.0.0-5
keystone (Ubuntu package) - update to 2:16.0.0-0ubuntu1.1
keystone (Ubuntu package) - update to 2:16.0.0-0ubuntu1.1
External References
- http://www.openwall.com/lists/oss-security/2019/12/11/8
- https://access.redhat.com/errata/RHSA-2019:4358
- https://bugs.launchpad.net/keystone/+bug/1855080
- https://review.opendev.org/#/c/697355/
- https://review.opendev.org/#/c/697611/
- https://review.opendev.org/#/c/697731/
- https://security.openstack.org/ossa/OSSA-2019-006.html