A flaw was discovered in the python-novajoin plugin, all versions up to, excluding 1.1.1, for Red Hat OpenStack Platform. The novajoin API lacked sufficient access control, allowing any keystone authenticated user to generate FreeIPA tokens.
References
Link | Resource |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10138 | Issue Tracking Third Party Advisory |
https://review.opendev.org/#/c/631240/ | Third Party Advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10138 | Issue Tracking Third Party Advisory |
https://review.opendev.org/#/c/631240/ | Third Party Advisory |
Configurations
History
No history.
Information
Published : 2019-07-30 17:15
Updated : 2024-11-21 04:18
NVD link : CVE-2019-10138
Mitre link : CVE-2019-10138
CVE.ORG link : CVE-2019-10138
JSON object : View
Products Affected
python
- novajoin
CWE