A flaw was discovered in the python-novajoin plugin, all versions up to, excluding 1.1.1, for Red Hat OpenStack Platform. The novajoin API lacked sufficient access control, allowing any keystone authenticated user to generate FreeIPA tokens.
"https://github.com/pypa/advisory-database/blob/main/vulns/novajoin/PYSEC-2019-192.yaml"