QID 982009

QID 982009: Python (pip) Security Update for keystone (GHSA-6m8p-x4qw-gh5j)

An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. The list of roles provided for an OAuth1 access token is silently ignored. Thus, when an access token is used to request a keystone token, the keystone token contains every role assignment the creator had for the project. This results in the provided keystone token having more role assignments than the creator intended, possibly giving unintended escalated access.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as High - 6.5 severity.
  • Solution
    Customers are advised to refer to GHSA-6m8p-x4qw-gh5j for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 982009

    Software Advisories
    Advisory ID Software Component Link
    GHSA-6m8p-x4qw-gh5j keystone URL Logo github.com/advisories/GHSA-6m8p-x4qw-gh5j