A flaw was discovered in the python-novajoin plugin, all versions up to, excluding 1.1.1, for Red Hat OpenStack Platform. The novajoin API lacked sufficient access control, allowing any keystone authenticated user to generate FreeIPA tokens.
{
"severity": "HIGH",
"github_reviewed": true,
"cwe_ids": [
"CWE-284"
],
"nvd_published_at": "2019-07-30T17:15:00Z",
"github_reviewed_at": "2020-03-12T16:53:49Z"
}