An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. Any user authenticated within a limited scope (trust/oauth/application credential) can create an EC2 credential with an escalated permission, such as obtaining admin while the user is on a limited viewer role. This potentially allows a malicious user to act as the admin on a project another user has the admin role on, which can effectively grant that user global admin privileges.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-0095 | An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. Any user authenticated within a limited scope (trust/oauth/application credential) can create an EC2 credential with an escalated permission, such as obtaining admin while the user is on a limited viewer role. This potentially allows a malicious user to act as the admin on a project another user has the admin role on, which can effectively grant that user global admin privileges. |
Github GHSA |
GHSA-chgw-36xv-47cw | OpenStack Keystone EC2 and/or credential endpoints are not protected from a scoped context |
Ubuntu USN |
USN-4480-1 | OpenStack Keystone vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T12:04:22.561Z
Reserved: 2020-05-06T00:00:00
Link: CVE-2020-12689
No data.
Status : Modified
Published: 2020-05-07T00:15:10.877
Modified: 2024-11-21T05:00:04.560
Link: CVE-2020-12689
OpenCVE Enrichment
No data.
EUVD
Github GHSA
Ubuntu USN