CVE-2018-20170
17.12.2018, 07:29
OpenStack Keystone through 14.0.1 has a user enumeration vulnerability because invalid usernames have much faster responses than valid ones for a POST /v3/auth/tokens request. NOTE: the vendor's position is that this is a hardening opportunity, and not necessarily an issue that should have an OpenStack Security AdvisoryEnginsight
Vendor | Product | Version |
---|---|---|
openstack | keystone | 𝑥 ≤ 14.0.1 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Common Weakness Enumeration