CVE-2019-19687
published 2019-12-09CVE-2019-19687: OpenStack Keystone 15.0.0 and 16.0.0 is affected by Data Leakage in the list credentials API. Any user with a role on a project is able to list any credentials…
PriorityP351high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
1.78%
75.7th percentile
OpenStack Keystone 15.0.0 and 16.0.0 is affected by Data Leakage in the list credentials API. Any user with a role on a project is able to list any credentials with the /v3/credentials API when enforce_scope is false. Users with a role on a project are able to view any other users' credentials, which could (for example) leak sign-on information for Time-based One Time Passwords (TOTP). Deployments with enforce_scope set to false are affected. (There will be a slight performance impact for the list credentials API once this issue is fixed.)
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | keystone | < keystone 2:16.0.0-5 (bookworm) | keystone 2:16.0.0-5 (bookworm) |
| openstack | keystone | — | — |
| openstack | keystone | — | — |
| openstack | keystone | >= 0 < 2:16.0.0-5 | 2:16.0.0-5 |
| openstack | keystone | >= 0 < 2:16.0.0-5 | 2:16.0.0-5 |
| openstack | keystone | >= 0 < 2:16.0.0-5 | 2:16.0.0-5 |
| openstack | keystone | >= 0 < 2:16.0.0-5 | 2:16.0.0-5 |
| openstack | keystone | >= 15.0.0 < 15.0.1 | 15.0.1 |
| openstack | keystone | >= 16.0.0 < 16.0.1 | 16.0.1 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:P/I:N/A:N
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
OpenStack Keystone vulnerability
vendor_ubuntu·2020-01-30
CVE-2019-19687 OpenStack Keystone vulnerability
Title: OpenStack Keystone vulnerability
Summary: OpenStack Keystone could be made to expose sensitive information over the
network.
Daniel Preussker discovered that OpenStack Keystone incorrectly handled the
list credentials API. A user with a role on the project could use this
issue to view any other user's credentials.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
openstack-keystone: Credentials API allows non-admin to list and retrieve all users credentials
vendor_redhat·2019-12-04·CVSS 8.8
CVE-2019-19687 [HIGH] CWE-522 openstack-keystone: Credentials API allows non-admin to list and retrieve all users credentials
openstack-keystone: Credentials API allows non-admin to list and retrieve all users credentials
OpenStack Keystone 15.0.0 and 16.0.0 is affected by Data Leakage in the list credentials API. Any user with a role on a project is able to list any credentials with the /v3/credentials API when enforce_scope is false. Users with a role on a project are able to view any other users' credentials, which could (for example) leak sign-on information for Time-based One Time Passwords (TOTP). Deployments with enforce_scope set to false are affected. (There will be a slight performance impact for the list credentials API once this issue is fixed.)
A disclosure vulnerability was found in openstack-keystone's credentials API. Users with a project role are able to list any credentials with the /v3/creden
Debian
CVE-2019-19687: keystone - OpenStack Keystone 15.0.0 and 16.0.0 is affected by Data Leakage in the list cre...
vendor_debian·2019·CVSS 8.8
CVE-2019-19687 [HIGH] CVE-2019-19687: keystone - OpenStack Keystone 15.0.0 and 16.0.0 is affected by Data Leakage in the list cre...
OpenStack Keystone 15.0.0 and 16.0.0 is affected by Data Leakage in the list credentials API. Any user with a role on a project is able to list any credentials with the /v3/credentials API when enforce_scope is false. Users with a role on a project are able to view any other users' credentials, which could (for example) leak sign-on information for Time-based One Time Passwords (TOTP). Deployments with enforce_scope set to false are affected. (There will be a slight performance impact for the list credentials API once this issue is fixed.)
Scope: local
bookworm: resolved (fixed in 2:16.0.0-5)
bullseye: resolved (fixed in 2:16.0.0-5)
forky: resolved (fixed in 2:16.0.0-5)
sid: resolved (fixed in 2:16.0.0-5)
trixie: resolved (fixed in 2:16.0.0-5)
GHSA
OpenStack Keystone Credential Leakage
ghsa·2022-05-24
CVE-2019-19687 [HIGH] CWE-522 OpenStack Keystone Credential Leakage
OpenStack Keystone Credential Leakage
OpenStack Keystone 15.0.0 and 16.0.0 is affected by Data Leakage in the list credentials API. Any user with a role on a project is able to list any credentials with the `/v3/credentials` API when `enforce_scope` is false. Users with a role on a project are able to view any other users' credentials, which could (for example) leak sign-on information for Time-based One Time Passwords (TOTP). Deployments with enforce_scope set to false are affected. (There will be a slight performance impact for the list credentials API once this issue is fixed.)
OSV
OpenStack Keystone Credential Leakage
osv·2022-05-24
CVE-2019-19687 [HIGH] OpenStack Keystone Credential Leakage
OpenStack Keystone Credential Leakage
OpenStack Keystone 15.0.0 and 16.0.0 is affected by Data Leakage in the list credentials API. Any user with a role on a project is able to list any credentials with the `/v3/credentials` API when `enforce_scope` is false. Users with a role on a project are able to view any other users' credentials, which could (for example) leak sign-on information for Time-based One Time Passwords (TOTP). Deployments with enforce_scope set to false are affected. (There will be a slight performance impact for the list credentials API once this issue is fixed.)
OSV
CVE-2019-19687: OpenStack Keystone 15
osv·2019-12-09·CVSS 8.8
CVE-2019-19687 [HIGH] CVE-2019-19687: OpenStack Keystone 15
OpenStack Keystone 15.0.0 and 16.0.0 is affected by Data Leakage in the list credentials API. Any user with a role on a project is able to list any credentials with the /v3/credentials API when enforce_scope is false. Users with a role on a project are able to view any other users' credentials, which could (for example) leak sign-on information for Time-based One Time Passwords (TOTP). Deployments with enforce_scope set to false are affected. (There will be a slight performance impact for the list credentials API once this issue is fixed.)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-19687 openstack-keystone: Credentials API allows non-admin to list and retrieve all users credentials [openstack-rdo]
bugzilla·2019-12-12·CVSS 8.8
CVE-2019-19687 [HIGH] CVE-2019-19687 openstack-keystone: Credentials API allows non-admin to list and retrieve all users credentials [openstack-rdo]
CVE-2019-19687 openstack-keystone: Credentials API allows non-admin to list and retrieve all users credentials [openstack-rdo]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of openstack-rdo.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Bugzilla
CVE-2019-19687 openstack-keystone: Credentials API allows non-admin to list and retrieve all users credentials
bugzilla·2019-12-10·CVSS 8.8
CVE-2019-19687 [HIGH] CVE-2019-19687 openstack-keystone: Credentials API allows non-admin to list and retrieve all users credentials
CVE-2019-19687 openstack-keystone: Credentials API allows non-admin to list and retrieve all users credentials
A vulnerability was found in Keystone's list credentials API. Any user with a role on a project is able to list any credentials with the /v3/credentials API when enforce_scope is false. Users with a role on a project are able to view any other users' credentials, which could leak sign-on information for Time-based One Time Passwords (TOTP) or othewise. Deployments running keystone with enforce_scope set to false are affected. There will be a slight performance impact for the list credentials API once this issue is fixed.
Affects: ==15.0.0, ==16.0.0
Discussion:
Upstream patches:
master: https://git.openstack.org/cgit/openstack/keystone/commit/?id=17c337dbdbfb9d548ad531c2ad0483c9
http://www.openwall.com/lists/oss-security/2019/12/11/8https://access.redhat.com/errata/RHSA-2019:4358https://bugs.launchpad.net/keystone/+bug/1855080https://review.opendev.org/#/c/697355/https://review.opendev.org/#/c/697611/https://review.opendev.org/#/c/697731/https://security.openstack.org/ossa/OSSA-2019-006.htmlhttps://usn.ubuntu.com/4262-1/http://www.openwall.com/lists/oss-security/2019/12/11/8https://access.redhat.com/errata/RHSA-2019:4358https://bugs.launchpad.net/keystone/+bug/1855080https://review.opendev.org/#/c/697355/https://review.opendev.org/#/c/697611/https://review.opendev.org/#/c/697731/https://security.openstack.org/ossa/OSSA-2019-006.htmlhttps://usn.ubuntu.com/4262-1/
2019-12-09
Published