
Cloud Vulnerability DB
A community-led vulnerabilities database
A vulnerability (CVE-2020-12690) was discovered in OpenStack Keystone versions before 15.0.1 and version 16.0.0. The vulnerability was reported by kay and disclosed on May 6, 2020. The issue affects the OAuth1 Token API functionality in OpenStack Keystone (OpenStack OSSA, Ubuntu Security).
The vulnerability occurs when the list of roles provided for an OAuth1 access token is silently ignored. When an OAuth1 access token is used to request a keystone token, the keystone token contains every role assignment the creator had for the project instead of the provided subset of roles. This behavior is caused by the token model not properly accounting for OAuth1-scoped tokens and incorrectly populating the roles (OpenStack OSSA).
The vulnerability results in the provided keystone token having more role assignments than the creator intended, potentially leading to unintended privilege escalation. This could allow users to gain unauthorized elevated access to project resources (OpenStack OSSA, Ubuntu Security).
The vulnerability requires an authenticated user with access to OAuth1 token functionality. The exploitation is limited to trusted users who need permissions to issue an OAuth1 token (OSS Security).
For affected versions, users can either upgrade to Keystone version 15.0.1 or later (except 16.0.0), or implement temporary mitigations. Temporary mitigations include disabling OAuth1 as an authentication method by removing it from the [auth]/methods config option in keystone.conf, or restricting access by disabling specific policy rules such as 'identity:create_consumer', 'identity:update_consumer', and 'identity:authorize_request_token' (OSS Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."