Impact
Tokens obtained through delegated authentication—OAuth1 access tokens, application credentials, and trusts—can be presented to Keystone’s token-method authentication endpoint to trigger reauthentication. When an application credential token is submitted without an explicit scope, Keystone mistakenly issues a new token scoped to the credential owner’s default project instead of the intended project, allowing an attacker to gain access beyond the intended boundaries.
Affected Systems
OpenStack Keystone versions earlier than 29.0.3 are affected whenever delegated authentication is enabled. Any deployment that permits OAuth1 access tokens, application credentials, or trusts without additional safeguards is vulnerable.
Risk and Exploitability
The CVSS score of 7.6 indicates a high severity. Although no EPSS score is available and the vulnerability is not listed in CISA KEV, the remote exploitability is clear: an attacker with valid delegated credentials can reauthenticate and obtain a token to the wrong project. The lack of a KEV listing suggests the vulnerability has not yet seen widespread exploitation, but the impact—loss of project isolation—underscores the need for timely remediation.
OpenCVE Enrichment
Debian DLA
Debian DSA