A flaw was discovered in the python-novajoin plugin, all versions up to, excluding 1.1.1, for Red Hat OpenStack Platform. The novajoin API lacked sufficient access control, allowing any keystone authenticated user to generate FreeIPA tokens.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-0097 | A flaw was discovered in the python-novajoin plugin, all versions up to, excluding 1.1.1, for Red Hat OpenStack Platform. The novajoin API lacked sufficient access control, allowing any keystone authenticated user to generate FreeIPA tokens. |
Github GHSA |
GHSA-xf8c-3cgx-fcwm | Improper Access Control in novajoin |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-04T22:10:10.017Z
Reserved: 2019-03-27T00:00:00
Link: CVE-2019-10138
No data.
Status : Modified
Published: 2019-07-30T17:15:12.390
Modified: 2024-11-21T04:18:29.793
Link: CVE-2019-10138
OpenCVE Enrichment
No data.
EUVD
Github GHSA