CVE-2020-12690

Description

An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. The list of roles provided for an OAuth1 access token is silently ignored. Thus, when an access token is used to request a keystone token, the keystone token contains every role assignment the creator had for the project. This results in the provided keystone token having more role assignments than the creator intended, possibly giving unintended escalated access.

Risk Information

Base Score
8.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.817

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities are fixed in Python-keystone 15.0.1Windows
Vulnerabilities CVE-2020-12690,CVE-2020-12692 are fixed in Python-keystone 16.0.0Windows
OpenStack identity service (USN-4480-1) keystone_13.0.4-0ubuntu1_all.debLinux
OpenStack identity service (USN-4480-1) python-keystone_13.0.4-0ubuntu1_all.debLinux
Multiple vulnerabilities are fixed in Python-keystone for linux 15.0.1Linux
Vulnerabilities CVE-2020-12690,CVE-2020-12692 are fixed in Python-keystone for linux 16.0.0Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234