Comment 2 for bug 1872733

Revision history for this message
kay (kay-diam) wrote : Re: Keystone V3 /credentials endpoint policy logic allows to change credentials owner or target project ID

In case, when "/credentials" endpoint is used to store a secret for TOTP (Time-based One-time Password), an attacker can set a TOTP secret for a victim user and it will be used to verify TOTP "passcode" along with all "totp" secrets, associated with a victim user.