Safety vulnerability ID: 36734
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Keystone has a user enumeration vulnerability because invalid usernames have much faster responses than valid ones for a POST /v3/auth/tokens request.
NOTE: the vendor's position is that this is a hardening opportunity, and not necessarily an issue that should have an OpenStack Security Advisory.
Latest version: 26.0.0
OpenStack Identity
** DISPUTED ** OpenStack Keystone through 14.0.1 has a user enumeration vulnerability because invalid usernames have much faster responses than valid ones for a POST /v3/auth/tokens request. NOTE: the vendor feels that the benefit to changing this might be too small relative to the performance degradation.
MISC:https://bugs.launchpad.net/keystone/+bug/1795800: https://bugs.launchpad.net/keystone/+bug/1795800
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application