A flaw was discovered in the python-novajoin plugin, all versions up to, excluding 1.1.1, for Red Hat OpenStack Platform. The novajoin API lacked sufficient access control, allowing any keystone authenticated user to generate FreeIPA tokens.
References
Link | Resource |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10138 | Issue Tracking Third Party Advisory |
https://review.opendev.org/#/c/631240/ | Third Party Advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10138 | Issue Tracking Third Party Advisory |
https://review.opendev.org/#/c/631240/ | Third Party Advisory |
Configurations
History
21 Nov 2024, 04:18
Type | Values Removed | Values Added |
---|---|---|
References | () https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10138 - Issue Tracking, Third Party Advisory | |
References | () https://review.opendev.org/#/c/631240/ - Third Party Advisory |
Information
Published : 2019-07-30 17:15
Updated : 2024-11-21 04:18
NVD link : CVE-2019-10138
Mitre link : CVE-2019-10138
CVE.ORG link : CVE-2019-10138
JSON object : View
Products Affected
python
- novajoin
CWE