keystone
PyPI40 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting keystonepage 1 of 1
- CVE-2012-3426NONECVSS 0.0✓ Fixed in 8.0.0a02012-07-31
OpenStack Keystone before 2012.1.1, as used in OpenStack Folsom before Folsom-1 and OpenStack Essex, does not properly implement token expiration, which allows remote authenticated users to bypass intended authorization restrictions by (1)…
- CVE-2012-3542NONECVSS 0.0✓ Fixed in c13d0ba606f7b2bdc609a7f388334e5efec3f3aa2012-09-05
vulnerable: 12.0.2 ... 28.0.0.0rc1 (54 versions)
OpenStack Keystone, as used in OpenStack Folsom before folsom-rc1 and OpenStack Essex (2012.1), allows remote attackers to add an arbitrary user to an arbitrary tenant via a request to update the user's default tenant to the administrative…
- CVE-2012-4413NONECVSS 0.0✓ Fixed in 2012.1.32012-09-18
vulnerable: 12.0.2 ... 26.0.0.0rc1 (49 versions)
OpenStack Keystone 2012.1.3 does not invalidate existing tokens when granting or revoking roles, which allows remote authenticated users to retain the privileges of the revoked roles.
- CVE-2012-4456NONECVSS 0.0✓ Fixed in 2012.1.22012-10-09
The (1) OS-KSADM/services and (2) tenant APIs in OpenStack Keystone Essex before 2012.1.2 and Folsom before folsom-2 do not properly validate X-Auth-Token, which allow remote attackers to read the roles for an arbitrary user or get, create…
- CVE-2012-4457NONECVSS 0.0✓ Fixed in 8.0.0a02012-10-09
OpenStack Keystone Essex before 2012.1.2 and Folsom before folsom-3 does not properly handle authorization tokens for disabled tenants, which allows remote authenticated users to access the tenant's resources by requesting a token for the …
- CVE-2012-5563NONECVSS 0.0✓ Fixed in f9d4766249a72d8f88d75dcf1575b28dd34966812012-12-18
vulnerable: 12.0.2 ... 28.0.0.0rc1 (54 versions)
OpenStack Keystone, as used in OpenStack Folsom 2012.2, does not properly implement token expiration, which allows remote authenticated users to bypass intended authorization restrictions by creating new tokens through token chaining. NOT…
- CVE-2012-5571MEDIUMCVSS 5.4✓ Fixed in 8.0.0a02012-12-18
A flaw was found in OpenStack Keystone. This vulnerability allows remote authenticated users to bypass intended authorization restrictions. This occurs because OpenStack Keystone does not properly handle EC2 (Elastic Compute Cloud) tokens …
- CVE-2013-0270MEDIUMCVSS 6.5✓ Fixed in 8.0.0a02013-04-12
A flaw was found in OpenStack Keystone. A remote attacker could exploit this vulnerability by sending a large HTTP request, specifically by providing a long tenant name when requesting a token. This could lead to a denial of service, consu…
- CVE-2013-0282NONECVSS 0.0✓ Fixed in 8.0.0a02013-04-12
OpenStack Keystone Grizzly before 2013.1, Folsom 2012.1.3 and earlier, and Essex does not properly check if the (1) user, (2) tenant, or (3) domain is enabled when using EC2-style authentication, which allows context-dependent attackers to…
- CVE-2013-1865NONECVSS 0.0✓ Fixed in 2012.2.42013-03-22
OpenStack Keystone Folsom (2012.2) does not properly perform revocation checks for Keystone PKI tokens when done through a server, which allows remote attackers to bypass intended access restrictions via a revoked PKI token.
- CVE-2013-2006NONECVSS 0.0✓ Fixed in 8.0.0a02013-05-21
OpenStack Identity (Keystone) Grizzly 2013.1.1, when DEBUG mode logging is enabled, logs the (1) admin_token and (2) LDAP password in plaintext, which allows local users to obtain sensitive by reading the log file.
- CVE-2013-2014NONECVSS 0.0✓ Fixed in 8.0.0a02014-06-02
OpenStack Identity (Keystone) before 2013.1 allows remote attackers to cause a denial of service (memory consumption and crash) via multiple long requests.
- CVE-2013-2059NONECVSS 0.0✓ Fixed in 8.0.0a02013-05-21
OpenStack Identity (Keystone) Folsom 2012.2.4 and earlier, Grizzly before 2013.1.1, and Havana does not immediately revoke the authentication token when deleting a user through the Keystone v2 API, which allows remote authenticated users t…
- CVE-2013-2255MEDIUMCVSS 5.9EG 5.9✓ Fixed in 8.0.0a02019-11-01
HTTPSConnections in OpenStack Keystone 2013, OpenStack Compute 2013.1, and possibly other OpenStack components, fail to validate server-side SSL certificates.
- CVE-2013-4294NONECVSS 0.0✓ Fixed in 2013.1.42013-09-23
The (1) mamcache and (2) KVS token backends in OpenStack Identity (Keystone) Folsom 2012.2.x and Grizzly before 2013.1.4 do not properly compare the PKI token revocation list with PKI tokens, which allow remote attackers to bypass intended…
- CVE-2013-4477NONECVSS 0.0✓ Fixed in 8.0.0a02013-11-02
The LDAP backend in OpenStack Identity (Keystone) Grizzly and Havana, when removing a role on a tenant for a user who does not have that role, adds the role to the user, which allows local users to gain privileges.
- CVE-2014-0204NONECVSS 0.0✓ Fixed in 8.0.0a02014-11-03
OpenStack Identity (Keystone) before 2014.1.1 does not properly handle when a role is assigned to a group that has the same ID as a user, which allows remote authenticated users to gain privileges that are assigned to a group with the same…
- CVE-2014-2237NONECVSS 0.0✓ Fixed in 8.0.0a02014-04-01
The memcache token backend in OpenStack Identity (Keystone) 2013.1 through 2.013.1.4, 2013.2 through 2013.2.2, and icehouse before icehouse-3, when issuing a trust token with impersonation enabled, does not include this token in the truste…
- CVE-2014-2828NONECVSS 0.0✓ Fixed in 8.0.0a02014-04-15
The V3 API in OpenStack Identity (Keystone) 2013.1 before 2013.2.4 and icehouse before icehouse-rc2 allows remote attackers to cause a denial of service (CPU consumption) via a large number of the same authentication method in a request, a…
- CVE-2014-3476NONECVSS 0.0✓ Fixed in 8.0.0a02014-06-17
OpenStack Identity (Keystone) before 2013.2.4, 2014.1 before 2014.1.2, and Juno before Juno-2 does not properly handle chained delegation, which allows remote authenticated users to gain privileges by leveraging a (1) trust or (2) OAuth to…
- CVE-2014-3621NONECVSS 0.0✓ Fixed in 8.0.0a02014-10-02
The catalog url replacement in OpenStack Identity (Keystone) before 2013.2.3 and 2014.1 before 2014.1.2.1 allows remote authenticated users to read sensitive configuration options via a crafted endpoint, as demonstrated by "$(admin_token)"…
- CVE-2014-5251NONECVSS 0.0✓ Fixed in 8.0.0a02014-08-25
The MySQL token driver in OpenStack Identity (Keystone) 2014.1.x before 2014.1.2.1 and Juno before Juno-3 stores timestamps with the incorrect precision, which causes the expiration comparison for tokens to fail and allows remote authentic…
- CVE-2014-5252NONECVSS 0.0✓ Fixed in 8.0.0a02014-08-25
The V3 API in OpenStack Identity (Keystone) 2014.1.x before 2014.1.2.1 and Juno before Juno-3 updates the issued_at value for UUID v2 tokens, which allows remote authenticated users to bypass the token expiration and retain access via a ve…
- CVE-2014-5253NONECVSS 0.0✓ Fixed in 8.0.0a02014-08-25
OpenStack Identity (Keystone) 2014.1.x before 2014.1.2.1 and Juno before Juno-3 does not properly revoke tokens when a domain is invalidated, which allows remote authenticated users to retain access via a domain-scoped token for that domai…
- CVE-2015-3646NONECVSS 0.0EG 0.0✓ Fixed in 2014.2.42015-05-12
OpenStack Identity (Keystone) before 2014.1.5 and 2014.2.x before 2014.2.4 logs the backend_argument configuration option content, which allows remote authenticated users to obtain passwords and other sensitive backend information by readi…
- CVE-2015-7546HIGHCVSS 7.5EG 7.5✓ Fixed in 8.1.02016-02-03
The identity service in OpenStack Identity (Keystone) before 2015.1.3 (Kilo) and 8.0.x before 8.0.2 (Liberty) and keystonemiddleware (formerly python-keystoneclient) before 1.5.4 (Kilo) and Liberty before 2.3.3 does not properly invalidate…
- CVE-2016-4911MEDIUMCVSS 4.3EG 4.3✓ Fixed in 9.0.12016-06-13
The Fernet Token Provider in OpenStack Identity (Keystone) 9.0.x before 9.0.1 (mitaka) allows remote authenticated users to prevent revocation of a chain of tokens and bypass intended access restrictions by rescoping a token.
- CVE-2017-2673MEDIUMCVSS 6.8EG 6.8✓ Fixed in 11.0.12018-07-19
vulnerable: 11.0.0
An authorization-check flaw was discovered in federation configurations of the OpenStack Identity service (keystone). An authenticated federated user could request permissions to a project and unintentionally be granted all related roles i…
- CVE-2018-20170MEDIUMCVSS 5.3EG 5.3✓ Fixed in 14.1.02018-12-17
vulnerable: 12.0.2 ... 14.0.1 (7 versions)
OpenStack Keystone through 14.0.1 has a user enumeration vulnerability because invalid usernames have much faster responses than valid ones for a POST /v3/auth/tokens request. NOTE: the vendor's position is that this is a hardening opportu…
- CVE-2019-19687HIGHCVSS 8.8EG 8.8✓ Fixed in 16.0.12019-12-09
vulnerable: 12.0.2 ... 16.0.0 (16 versions)
OpenStack Keystone 15.0.0 and 16.0.0 is affected by Data Leakage in the list credentials API. Any user with a role on a project is able to list any credentials with the /v3/credentials API when enforce_scope is false. Users with a role on …
- CVE-2020-12689HIGHCVSS 8.8EG 8.8✓ Fixed in 15.0.12020-05-07
vulnerable: 12.0.2 ... 15.0.0 (12 versions)
An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. Any user authenticated within a limited scope (trust/oauth/application credential) can create an EC2 credential with an escalated permission, such as obtaining admin …
- CVE-2020-12690HIGHCVSS 8.8EG 8.8✓ Fixed in 15.0.12020-05-07
vulnerable: 12.0.2 ... 15.0.0 (12 versions)
An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. The list of roles provided for an OAuth1 access token is silently ignored. Thus, when an access token is used to request a keystone token, the keystone token contains…
- CVE-2020-12691HIGHCVSS 8.8EG 8.8✓ Fixed in 15.0.12020-05-07
vulnerable: 12.0.2 ... 15.0.0 (12 versions)
An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. Any authenticated user can create an EC2 credential for themselves for a project that they have a specified role on, and then perform an update to the credential user…
- CVE-2020-12692MEDIUMCVSS 5.4EG 5.4✓ Fixed in 15.0.12020-05-07
vulnerable: 12.0.2 ... 15.0.0 (12 versions)
An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. The EC2 API doesn't have a signature TTL check for AWS Signature V4. An attacker can sniff the Authorization header, and then use it to reissue an OpenStack token an …
- CVE-2021-3563HIGHCVSS 7.4EG 9.12022-08-26
vulnerable: 12.0.2 ... 21.0.0.0rc1 (34 versions)
A flaw was found in openstack-keystone. Only the first 72 characters of an application secret are verified allowing attackers bypass some password complexity which administrators may be counting on. The highest threat from this vulnerabili…
- CVE-2021-38155HIGHCVSS 7.5EG 7.5✓ Fixed in 19.0.12021-08-06
vulnerable: 19.0.0
OpenStack Keystone 10.x through 16.x before 16.0.2, 17.x before 17.0.1, 18.x before 18.0.1, and 19.x before 19.0.1 allows information disclosure during account locking (related to PCI DSS features). By guessing the name of an account and f…
- CVE-2025-65073HIGHCVSS 7.5EG 7.5✓ Fixed in 28.0.02025-11-17
vulnerable: 28.0.0.0rc1
OpenStack Keystone before 26.0.1, 27.0.0, and 28.0.0 allows a /v3/ec2tokens or /v3/s3tokens request with a valid AWS Signature to provide Keystone authorization.
- CVE-2026-33551LOWCVSS 3.5EG 3.5✓ Fixed in 26.1.12026-04-10
vulnerable: 14.0.0 ... 26.1.0 (46 versions)
An issue was discovered in OpenStack Keystone 14 through 26 before 26.1.1, 27.0.0, 28.0.0, and 29.0.0. Restricted application credentials can create EC2 credentials. By using a restricted application credential to call the EC2 credential c…
- CVE-2026-40683HIGHCVSS 7.7EG 7.7✓ Fixed in 28.0.12026-04-14
vulnerable: 12.0.2 ... 28.0.0.0rc1 (55 versions)
In OpenStack Keystone before 28.0.1, the LDAP identity backend does not convert the user enabled attribute to a boolean when the user_enabled_invert configuration option is False (the default). The _ldap_res_to_model method in the UserApi …
- CVE-2026-43001HIGHCVSS 7.9EG 7.92026-05-01
vulnerable: 13.0.2 ... 29.0.1 (59 versions)
An issue was discovered in OpenStack Keystone 13 through 29. POST /v3/credentials did not validate that the caller-supplied project_id for an EC2-type credential matched the project of the authenticating application credential. This allowe…
Check whether keystone is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for keystone CVEs against the assets you own.
Start Free Scan →