cbcvebase.
CVE-2020-12690
published 2020-05-07

CVE-2020-12690: An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. The list of roles provided for an OAuth1 access token is silently ignored. Thus, when…

PriorityP350high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
1.90%
77.3th percentile
An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. The list of roles provided for an OAuth1 access token is silently ignored. Thus, when an access token is used to request a keystone token, the keystone token contains every role assignment the creator had for the project. This results in the provided keystone token having more role assignments than the creator intended, possibly giving unintended escalated access.

Affected

10 ranges
VendorProductVersion rangeFixed in
debiankeystone< keystone 2:17.0.0~rc2-1 (bookworm)keystone 2:17.0.0~rc2-1 (bookworm)
openstackkeystone< 15.0.115.0.1
openstackkeystone
openstackkeystone>= 0 < 2:17.0.0~rc2-12:17.0.0~rc2-1
openstackkeystone>= 0 < 2:17.0.0~rc2-12:17.0.0~rc2-1
openstackkeystone>= 0 < 2:17.0.0~rc2-12:17.0.0~rc2-1
openstackkeystone>= 0 < 2:17.0.0~rc2-12:17.0.0~rc2-1
openstackkeystone>= 0 < 15.0.115.0.1
openstackkeystone>= 0 < 2:13.0.4-0ubuntu12:13.0.4-0ubuntu1
openstackkeystone>= 16.0.0.0rc1 < 16.0.016.0.0

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
vendor_ubuntu8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.