QID 982009
QID 982009: Python (pip) Security Update for keystone (GHSA-6m8p-x4qw-gh5j)
An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. The list of roles provided for an OAuth1 access token is silently ignored. Thus, when an access token is used to request a keystone token, the keystone token contains every role assignment the creator had for the project. This results in the provided keystone token having more role assignments than the creator intended, possibly giving unintended escalated access.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-6m8p-x4qw-gh5j for updates pertaining to this vulnerability.
Vendor References
- GHSA-6m8p-x4qw-gh5j -
github.com/advisories/GHSA-6m8p-x4qw-gh5j
CVEs related to QID 982009
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-6m8p-x4qw-gh5j | keystone |
|