PublicDateAtUSN: 2019-12-09 18:15:00 UTC Candidate: CVE-2019-19687 PublicDate: 2019-12-09 18:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19687 https://review.opendev.org/#/c/697355/ https://review.opendev.org/#/c/697611/ https://review.opendev.org/#/c/697731/ https://ubuntu.com/security/notices/USN-4262-1 Description: OpenStack Keystone 15.0.0 and 16.0.0 is affected by Data Leakage in the list credentials API. Any user with a role on a project is able to list any credentials with the /v3/credentials API when enforce_scope is false. Users with a role on a project are able to view any other users' credentials, which could (for example) leak sign-on information for Time-based One Time Passwords (TOTP). Deployments with enforce_scope set to false are affected. (There will be a slight performance impact for the list credentials API once this issue is fixed.) Ubuntu-Description: Notes: mdeslaur> introduced in keystone 15.0.0, present in 16.0.0 too Mitigation: Bugs: https://bugs.launchpad.net/keystone/+bug/1855080 Priority: medium Discovered-by: Daniel 'f0o' Preussker Assigned-to: mdeslaur CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H [8.8 HIGH] Patches_keystone: upstream: https://opendev.org/openstack/keystone/commit/17947516b0095c51da5cff94771247f2e7c44ee6 (15.x) upstream: https://opendev.org/openstack/keystone/commit/bd3f63787151183f4daa43578aa491856fefae5b (16.x) upstream_keystone: needs-triage precise/esm_keystone: DNE trusty_keystone: ignored (out of standard support) trusty/esm_keystone: DNE xenial_keystone: not-affected (2:9.3.0-0ubuntu3.2) esm-infra/xenial_keystone: not-affected (2:9.3.0-0ubuntu3.2) bionic_keystone: not-affected (2:13.0.2-0ubuntu1) disco_keystone: ignored (reached end-of-life) eoan_keystone: released (2:16.0.0-0ubuntu1.1) devel_keystone: released (2:17.0.0~b1~git2019121613.db81fee63-0ubuntu1)