keystone_json_assignment backend granted access to any project for users in user-project-map.json
Vulnerability Description
The keystone-json-assignment package in SUSE Openstack Cloud 8 before commit d7888c75505465490250c00cc0ef4bb1af662f9f every user listed in the /etc/keystone/user-project-map.json was assigned full "member" role access to every project. This allowed these users to access, modify, create and delete arbitrary resources, contrary to expectations.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-3683
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Kurt Garloff by SUSE
More from SUSE
View All →Affected Vendor
SUSE
View all reports →