Authentication Weakness in keystone
High severity
GitHub Reviewed
Published
Jun 7, 2018
to the GitHub Advisory Database
•
Updated Jan 9, 2023
Description
Published to the GitHub Advisory Database
Jun 7, 2018
Reviewed
Jun 16, 2020
Last updated
Jan 9, 2023
Versions of
keystone
prior to 0.3.16 are affected by a partial authentication bypass vulnerability. In the default sign in functionality, if an attacker provides a full and correct password, yet only provides part of the associated email address, authentication will be granted.Recommendation
Update to version 0.3.16 or later.
References