All errata/sisyphus/ALT-PU-2019-4237-1
ALT-PU-2019-4237-1

Package update openstack-keystone in branch sisyphus

Version14.1.0-alt1
Published2019-04-23
Max severityMEDIUM
Severity:

Closed issues (1)

CVE-2018-20170
MEDIUM5.3

OpenStack Keystone through 14.0.1 has a user enumeration vulnerability because invalid usernames have much faster responses than valid ones for a POST /v3/auth/tokens request. NOTE: the vendor's position is that this is a hardening opportunity, and not necessarily an issue that should have an OpenStack Security Advisory

Published: 2018-12-17Modified: 2024-11-21
CVSS 2.0MEDIUM 5.0
CVSS:2.0/AV:N/AC:L/Au:N/C:P/I:N/A:N
CVSS 3.xMEDIUM 5.3
CVSS:3.x/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N