PT-2026-97852 · Openstack · Openstack Zaqar
CVE-2026-97404
·
Published
2026-09-24
·
Updated
2026-09-26
CVSS v4.0
9.2
Critical
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
OpenStack Zaqar versions prior to 22.0.2
Description
WSGI transport mishandles the
URL-Signature header. An unauthenticated remote attacker who knows a target project's UUID can bypass Keystone authentication and pre-signed URL verification by sending a request with an empty URL-Signature header. This allows the attacker to read, enumerate, create, and delete the project's queues, messages, claims, and subscriptions. In deployments using admin mode, claiming an administrative role further enables administrative operations, such as managing pools and flavors. This issue only affects deployments using WSGI transport with a configured authentication strategy; websocket transport is not affected.Recommendations
Update to version 22.0.2 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openstack Zaqar