CVE-2018-14432

MEDIUM

OpenStack Keystone <13.0.0 - Auth Bypass

Title source: llm

Description

In the Federation component of OpenStack Keystone before 11.0.4, 12.0.0, and 13.0.0, an authenticated "GET /v3/OS-FEDERATION/projects" request may bypass intended access restrictions on listing projects. An authenticated user may discover projects they have no authority to access, leaking all projects in the deployment and their attributes. Only Keystone with the /v3/OS-FEDERATION endpoint enabled via policy.json is affected.

Scores

CVSS v3 5.3
EPSS 0.0114
EPSS Percentile 78.1%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N

Classification

CWE
CWE-200
Status published

Affected Products (7)

debian/debian_linux
redhat/openstack
redhat/openstack
redhat/openstack
openstack/keystone < 11.0.4
openstack/keystone
openstack/keystone

Timeline

Published Jul 31, 2018
Tracked Since Feb 18, 2026