← Vulnerability feed

Vulnerability record · CVE-2019-19687 · published 9 December 2019

CVE-2019-19687: Openstack keystone insufficiently protected credentials vulnerability

Openstack · Keystone

OpenStack Keystone 15.0.0 and 16.0.0 is affected by Data Leakage in the list credentials API. Any user with a role on a project is able to list any credentials with the /v3/credentials API when enforce_scope is false. Users with a role on a project are able to view any other users' credentials, which could (for example) leak sign-on information for Time-based One Time Passwords (TOTP). Deployments with enforce_scope set to false are affected. (There will be a slight performance impact for the list credentials API once this issue is fixed.)

8.8 CVSS 3.1 High EPSS 1.8% · top 22.6% CWE-522 · Insufficiently protected credentials
8.8CVSS 3.1 base score, v2 3.5
1.8%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
16References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

OpenStack Keystone 15.0.0 and 16.0.0 is affected by Data Leakage in the list credentials API. Any user with a role on a project is able to list any credentials with the /v3/credentials API when enforce_scope is false. Users with a role on a project are able to view any other users' credentials, which could (for example) leak sign-on information for Time-based One Time Passwords (TOTP). Deployments with enforce_scope set to false are affected. (There will be a slight performance impact for the list credentials API once this issue is fixed.)

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-19687 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2026-42998Openstack keystone incorrect authorization vulnerabilityAn issue was discovered in OpenStack Keystone before 29.0.2. The Keystone application credential authentication plugin does not verify that the user …EPSS 0.40%8.8CVE-2026-42999Openstack keystone incorrect authorization vulnerabilityAn issue was discovered in OpenStack Keystone before 29.0.2. The Keystone RBAC policy enforcer in enforce_call unconditionally merges the raw JSON re…EPSS 0.42%8.8CVE-2026-43000Openstack keystone incorrect authorization vulnerabilityAn issue was discovered in OpenStack Keystone before 29.0.2. When combined with an application credential impersonation vulnerability, an attacker wi…EPSS 0.43%8.8CVE-2020-12689Openstack keystone improper privilege management vulnerabilityAn issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. Any user authenticated within a limited scope (trust/oauth/application crede…EPSS 1.6%8.8CVE-2020-12690Openstack keystone insufficient session expiration vulnerabilityAn issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. The list of roles provided for an OAuth1 access token is silently ignored. T…EPSS 1.9%8.8CVE-2020-12691Openstack keystone incorrect authorization vulnerabilityAn issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. Any authenticated user can create an EC2 credential for themselves for a pro…EPSS 4.9%8.1CVE-2026-44394Openstack keystone incorrect authorization vulnerabilityAn issue was discovered in OpenStack Keystone before 29.0.2. The Keystone federated token rescoping mechanism does not propagate the original token's…EPSS 0.32%8.0CVE-2026-43001Openstack keystone incorrect authorization vulnerabilityAn issue was discovered in OpenStack Keystone before 29.0.2. POST /v3/credentials did not validate that the caller-supplied project_id for an EC2-typ…EPSS 0.59%

Source: NIST National Vulnerability Database (record CVE-2019-19687), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.