USN-7926-1
Dashboard / Vulnerabilities / USN-7926-1
USN-7926-1
Summary: keystone vulnerabilities
Details: Kay discovered that OpenStack Keystone incorrectly handled the ec2tokens and s3tokens APIs. A remote attacker could possibly use this issue to obtain unauthorized access and escalate privileges. (CVE-2025-65073) It was discovered that OpenStack Keystone only validated the first 72 bytes of an application secret. An attacker could possibly use this issue to bypass password complexity. (CVE-2021-3563) It was discovered that OpenStack Keystone had a time lag before a token should be revoked by the security policy. A remote administrator could use this issue to maintain access for longer than expected. (CVE-2022-2447)
References: https://ubuntu.com/security/notices/USN-7926-1, https://ubuntu.com/security/CVE-2021-3563, https://ubuntu.com/security/CVE-2022-2447, https://ubuntu.com/security/CVE-2025-65073
Affected packages
Package
Name: keystone
Purl: pkg:deb/ubuntu/keystone@2:21.0.1-0ubuntu2.1?arch=source&distro=jammy
Affected ranges
Type: ECOSYSTEM
Events:
