Back

MEDIUM

openstack-keystone: Information Exposure through /v3/OS-FEDERATION/projects

Published Jul 31, 2018

Description

In the Federation component of OpenStack Keystone before 11.0.4, 12.0.0, and 13.0.0, an authenticated "GET /v3/OS-FEDERATION/projects" request may bypass intended access restrictions on listing projects. An authenticated user may discover projects they have no authority to access, leaking all projects in the deployment and their attributes. Only Keystone with the /v3/OS-FEDERATION endpoint enabled via policy.json is affected.

Affected products

Remediation

Red Hat statement

Red Hat Quay does not include the vulnerable keystone/federation/controllers.py file fixed in [1] [1] https://review.opendev.org/c/openstack/keystone/+/585782/

Metrics

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jul 31, 2018
Updated Aug 5, 2024
Reserved Jul 19, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Jul 25, 2018