A flaw was discovered in the python-novajoin plugin, all versions up to, excluding 1.1.1, for Red Hat OpenStack Platform. The novajoin API lacked sufficient access control, allowing any keystone authenticated user to generate FreeIPA tokens.
References
Link | Resource |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10138 | Issue Tracking Third Party Advisory |
https://review.opendev.org/#/c/631240/ | Third Party Advisory |
Configurations
Information
Published : 2019-07-30 10:15
Updated : 2020-09-30 07:08
NVD link : CVE-2019-10138
Mitre link : CVE-2019-10138
JSON object : View
CWE
Products Affected
python
- novajoin