1.3.0
8 years ago
5 years ago
Known vulnerabilities in the novajoin package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
novajoin is a python package provides a dynamic vendordata plugin for the OpenStack nova metadata service to manage host instantiation in an IPA server. Affected versions of this package are vulnerable to Improper Access Control. The novajoin API lacked sufficient access control, allowing any keystone authenticated user to generate FreeIPA tokens How to fix Improper Access Control? Upgrade | [,1.1.1) |