CVE-2018-14432
MEDIUMOpenStack Keystone <13.0.0 - Auth Bypass
Title source: llmDescription
In the Federation component of OpenStack Keystone before 11.0.4, 12.0.0, and 13.0.0, an authenticated "GET /v3/OS-FEDERATION/projects" request may bypass intended access restrictions on listing projects. An authenticated user may discover projects they have no authority to access, leaking all projects in the deployment and their attributes. Only Keystone with the /v3/OS-FEDERATION endpoint enabled via policy.json is affected.
References (6)
Scores
CVSS v3
5.3
EPSS
0.0114
EPSS Percentile
78.1%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Classification
CWE
CWE-200
Status
published
Affected Products (7)
debian/debian_linux
redhat/openstack
redhat/openstack
redhat/openstack
openstack/keystone
< 11.0.4
openstack/keystone
openstack/keystone
Timeline
Published
Jul 31, 2018
Tracked Since
Feb 18, 2026