Impact
A flaw in OpenStack Keystone allows an attacker holding a delegated authentication token—such as an OAuth1 access token, an application credential, or a trust-scoped token—to create new long‑lived credentials or authorize additional delegations that persist beyond the lifetime of the original token. The delegation restrictions that are supposed to block these actions do not consistently apply to all delegated token types, giving an OAuth1‑scoped token the ability to create application credentials or authorise OAuth1 request tokens even when such operations are otherwise forbidden. This bypasses normal authorization controls, enabling an attacker to obtain credentials that permit broader or longer‑lasting access than intended.
Affected Systems
OpenStack Keystone versions earlier than 29.0.3. Any Keystone deployment that permits delegated authentication through OAuth1 access tokens, application credentials, or trust-based authentication is vulnerable.
Risk and Exploitability
The CVSS score of 7.6 categorises this vulnerability as high severity. Although the EPSS score is not provided, the exploitation of this weakness would require only a valid delegated token, which could be obtained through legitimate authentication flows or potentially stolen credentials. The attack vector is network‑based, involving the Keystone API. The vulnerability is not listed in CISA’s KEV catalog; however, the high CVSS score combined with the broad applicability of the affected token types indicates a significant risk to confidentiality and integrity of privileged credentials. Mitigation by applying the stated patch or disabling the affected delegated authentication mechanisms is essential to prevent the creation of unauthorized credentials.
OpenCVE Enrichment
Debian DLA
Debian DSA