Safety vulnerability ID: 37318
The information on this page was manually curated by our Cybersecurity Intelligence Team.
[This advisory has been limited. Please create a free account to view the full advisory.]
Latest version: 1.2.0
Nova integration to enroll IPA clients
[This affected versions has been limited. Please create a free account to view the full affected versions.]
[This fixed versions has been limited. Please create a free account to view the full fixed versions.]
A flaw was discovered in the python-novajoin plugin, all versions up to, excluding 1.1.1, for Red Hat OpenStack Platform. The novajoin API lacked sufficient access control, allowing any keystone authenticated user to generate FreeIPA tokens.
CONFIRM:https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10138: https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10138
MISC:https://review.opendev.org/#/c/631240/: https://review.opendev.org/#/c/631240/
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application