A flaw was found in python-novajoin plugin for Openstack. Lack of proper access control permits generation of tokens from authenticated users for HTTP calls to novajoin API.
Name: Grzegorz Grasza (Red Hat)
This issue has been addressed in the following products:
Red Hat OpenStack Platform 13.0 (Queens)
Via RHSA-2019:1728 https://access.redhat.com/errata/RHSA-2019:1728
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):