Authentication Weakness in keystone
Moderate severity
GitHub Reviewed
Published
Aug 19, 2020
to the GitHub Advisory Database
•
Updated Jan 9, 2023
Withdrawn
This advisory was withdrawn on Aug 19, 2020
Description
Reviewed
May 29, 2019
Published to the GitHub Advisory Database
Aug 19, 2020
Withdrawn
Aug 19, 2020
Last updated
Jan 9, 2023
There is an authentication weakness vulnerability in keystone before version 0.3.16. Due to a bug in the the default sign in functionality, incomplete email addresses could be matched. A correct password is still required to complete sign in.
References