CVE-2018-14432
Summary
| CVE | CVE-2018-14432 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-07-31 14:29:00 UTC |
| Updated | 2021-08-04 17:15:00 UTC |
| Description | In the Federation component of OpenStack Keystone before 11.0.4, 12.0.0, and 13.0.0, an authenticated "GET /v3/OS-FEDERATION/projects" request may bypass intended access restrictions on listing projects. An authenticated user may discover projects they have no authority to access, leaking all projects in the deployment and their attributes. Only Keystone with the /v3/OS-FEDERATION endpoint enabled via policy.json is affected. |
Risk And Classification
Problem Types: CWE-200
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Debian | Debian Linux | 9.0 | All | All | All |
| Operating System | Debian | Debian Linux | 9.0 | All | All | All |
| Application | Openstack | Keystone | All | All | All | All |
| Application | Openstack | Keystone | 12.0.0 | All | All | All |
| Application | Openstack | Keystone | 13.0.0 | All | All | All |
| Application | Openstack | Keystone | All | All | All | All |
| Application | Openstack | Keystone | 12.0.0 | All | All | All |
| Application | Openstack | Keystone | 13.0.0 | All | All | All |
| Application | Redhat | Openstack | 10 | All | All | All |
| Application | Redhat | Openstack | 10.0 | All | All | All |
| Application | Redhat | Openstack | 12 | All | All | All |
| Application | Redhat | Openstack | 12.0 | All | All | All |
| Application | Redhat | Openstack | 13 | All | All | All |
| Application | Redhat | Openstack | 13.0 | All | All | All |
| Application | Redhat | Openstack | 10.0 | All | All | All |
| Application | Redhat | Openstack | 12.0 | All | All | All |
| Application | Redhat | Openstack | 13.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Red Hat Customer Portal | REDHAT | access.redhat.com | Vendor Advisory |
| Red Hat Customer Portal | REDHAT | access.redhat.com | Vendor Advisory |
| Red Hat Customer Portal | REDHAT | access.redhat.com | Vendor Advisory |
| Debian -- Security Information -- DSA-4275-1 keystone | DEBIAN | www.debian.org | Third Party Advisory |
| oss-security - [OSSA-2018-002] GET /v3/OS-FEDERATION/projects leaks project information (CVE-2018-14432) | MLIST | www.openwall.com | Mailing List, Patch, Third Party Advisory |
| OpenStack Keystone CVE-2018-14432 Information Disclosure Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.