AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2018-14432

MEDIUM · CVSS 5.3 EPSS 1.62%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2018-07-31 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2018-14432
Severity
MEDIUM
CVSS
5.3
EPSS
1.62%

Original NVD Description

In the Federation component of OpenStack Keystone before 11.0.4, 12.0.0, and 13.0.0, an authenticated "GET /v3/OS-FEDERATION/projects" request may bypass intended access restrictions on listing projects. An authenticated user may discover projects they have no authority to access, leaking all projects in the deployment and their attributes. Only Keystone with the /v3/OS-FEDERATION endpoint enabled via policy.json is affected.