GHSA-cc99-whm5-mmq3
Dashboard / Vulnerabilities / GHSA-cc99-whm5-mmq3
GHSA-cc99-whm5-mmq3
Summary: Openstack Keystone Incorrect Authorization vulnerability
Details: A flaw was found in openstack-keystone, only the first 72 characters of an application secret are verified allowing attackers bypass some password complexity which administrators may be counting on. The highest threat from this vulnerability is to data confidentiality and integrity. A [patch](https://opendev.org/openstack/keystone/commit/7859ed26003858ebfd9a5e866b43f1a6a9e83dca) is available.
References: https://nvd.nist.gov/vuln/detail/CVE-2021-3563, https://access.redhat.com/security/cve/CVE-2021-3563, https://bugs.launchpad.net/ossa/+bug/1901891, https://bugzilla.redhat.com/show_bug.cgi?id=1962908, https://lists.debian.org/debian-lts-announce/2024/01/msg00007.html, https://opendev.org/openstack/keystone, https://opendev.org/openstack/keystone/commit/7859ed26003858ebfd9a5e866b43f1a6a9e83dca, https://review.opendev.org/c/openstack/keystone/+/803641, https://review.opendev.org/c/openstack/keystone/+/828595, https://review.opendev.org/c/openstack/keystone/+/856489, https://security-tracker.debian.org/tracker/CVE-2021-3563
Affected packages
Package
Name: keystone
Purl: pkg:pypi/keystone
Affected ranges
Type: ECOSYSTEM
Events:
