An issue was discovered in OpenStack Keystone before 15.0.1, and...
Vulnerability Description
An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. Any user authenticated within a limited scope (trust/oauth/application credential) can create an EC2 credential with an escalated permission, such as obtaining admin while the user is on a limited viewer role. This potentially allows a malicious user to act as the admin on a project another user has the admin role on, which can effectively grant that user global admin privileges.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-12689
Credits & Attribution
No credits recorded in the NVD database.
References
- https://security.openstack.org/ossa/OSSA-2020-004.html
- https://bugs.launchpad.net/keystone/+bug/1872735
- https://www.openwall.com/lists/oss-security/2020/05/06/5
- http://www.openwall.com/lists/oss-security/2020/05/07/2
- https://lists.apache.org/thread.html/re4ffc55cd2f1b55a26e07c83b3c22c3fe4bae6054d000a57fb48d8c2%40%3Ccommits.druid.apache.org%3E
- https://usn.ubuntu.com/4480-1/
More from openstack
View All →Affected Vendor
openstack
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.