Safety vulnerability ID: 37318
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Novajoin 1.1.1 includes a fix for CVE-2019-10138: A flaw was discovered in the python-novajoin plugin, all versions up to, excluding 1.1.1, for Red Hat OpenStack Platform. The novajoin API lacked sufficient access control, allowing any keystone authenticated user to generate FreeIPA tokens.
Latest version: 1.2.0
Nova integration to enroll IPA clients
A flaw was discovered in the python-novajoin plugin, all versions up to, excluding 1.1.1, for Red Hat OpenStack Platform. The novajoin API lacked sufficient access control, allowing any keystone authenticated user to generate FreeIPA tokens.
CONFIRM:https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10138: https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10138
MISC:https://review.opendev.org/#/c/631240/: https://review.opendev.org/#/c/631240/
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application