keystone@28.0.2

OpenStack Identity

  • latest version

    29.0.2

  • latest non vulnerable version

  • first published

    7 years ago

  • latest version published

    29 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the keystone package. This does not include vulnerabilities belonging to this package’s dependencies.

    Fix vulnerabilities automatically

    Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

    Fix for free
    VulnerabilityVulnerable Version
    • L
    Authorization Bypass Through User-Controlled Key

    keystone is a package that provides authentication, authorization and service discovery mechanisms via HTTP primarily for use by projects in the OpenStack family.

    Affected versions of this package are vulnerable to Authorization Bypass Through User-Controlled Key via injection of arbitrary policy target attributes in the request body. An attacker can gain unauthorized access to other users' resources and escalate privileges by including target IDs in the request payload.

    How to fix Authorization Bypass Through User-Controlled Key?

    Upgrade keystone to version 29.0.2 or higher.

    [14.0.0,29.0.2)
    • L
    Incorrect Implementation of Authentication Algorithm

    keystone is a package that provides authentication, authorization and service discovery mechanisms via HTTP primarily for use by projects in the OpenStack family.

    Affected versions of this package are vulnerable to Incorrect Implementation of Authentication Algorithm in the authentication process. An attacker can gain unauthorized access to project-scoped resources and perform actions as another user by using valid application credentials within a shared project context. This is only exploitable if the attacker possesses valid application credentials and shares a project context with the victim.

    How to fix Incorrect Implementation of Authentication Algorithm?

    Upgrade keystone to version 29.0.2 or higher.

    [14.0.0,29.0.2)
    • L
    Insufficient Session Expiration

    keystone is a package that provides authentication, authorization and service discovery mechanisms via HTTP primarily for use by projects in the OpenStack family.

    Affected versions of this package are vulnerable to Insufficient Session Expiration via the federated token rescoping process. An attacker can maintain persistent access by repeatedly rescoping tokens before their expiry, thereby bypassing configured token lifetime restrictions.

    How to fix Insufficient Session Expiration?

    Upgrade keystone to version 29.0.2 or higher.

    [14.0.0,29.0.2)
    • L
    Incorrect Privilege Assignment

    keystone is a package that provides authentication, authorization and service discovery mechanisms via HTTP primarily for use by projects in the OpenStack family.

    Affected versions of this package are vulnerable to Incorrect Privilege Assignment through the improper validation of delegated roles in the trust creation process. An attacker can obtain administrative privileges and maintain persistent access by chaining application credential impersonation with trust exploitation.

    How to fix Incorrect Privilege Assignment?

    Upgrade keystone to version 29.0.2 or higher.

    [14.0.0,29.0.2)
    • M
    Incorrect Authorization

    keystone is a package that provides authentication, authorization and service discovery mechanisms via HTTP primarily for use by projects in the OpenStack family.

    Affected versions of this package are vulnerable to Incorrect Authorization in the POST /v3/credentials endpoint. An attacker can gain unauthorized access to resources across different projects by supplying a mismatched project_id when creating EC2-type credentials, which allows lateral movement within the role footprint of the credential owner.

    How to fix Incorrect Authorization?

    Upgrade keystone to version 29.0.2 or higher.

    [13.0.2,29.0.2)
    • C
    Access Control Bypass

    keystone is a package that provides authentication, authorization and service discovery mechanisms via HTTP primarily for use by projects in the OpenStack family.

    Affected versions of this package are vulnerable to Access Control Bypass via the ec2tokens or s3tokens process when a request with a valid AWS Signature is accepted for authorization. An attacker can gain unauthorized access by submitting specially crafted requests containing valid AWS Signatures.

    How to fix Access Control Bypass?

    Upgrade keystone to version 29.0.0.0rc1 or higher.

    [0,29.0.0.0rc1)