There is an authentication weakness vulnerability in keystone before version 0.3.16. Due to a bug in the the default sign in functionality, incomplete email addresses could be matched. A correct password is still required to complete sign in.
{
"cwe_ids": [],
"github_reviewed": true,
"github_reviewed_at": "2019-05-29T19:21:31Z",
"nvd_published_at": null,
"severity": "MODERATE"
}