PT-2026-81880 · Openstack · Keystone
CVSS v4.0
7.6
High
| Vector | AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
OpenStack Keystone versions prior to 29.0.3
Description
Tokens obtained through delegated authentication mechanisms, such as OAuth1 access tokens, application credentials, or trusts, can be submitted to the token-method authentication path for reauthentication. This allows an attacker to escape the intended project scope. Specifically, when an application credential token is presented without an explicit scope, the system issues a new token scoped to the default project of the credential owner instead of the project for which the credential was originally issued, thereby bypassing project boundaries.
Recommendations
Update OpenStack Keystone to version 29.0.3 or later.
Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Keystone