CVE-2025-65073: [OSSA-2025-002] OpenStack Keystone: Unauthenticated access to EC2/S3 token endpoints can grant Keystone authorization (CVE-2025-65073)
OpenStack Keystone before 26.0.1, 27.0.0, and 28.0.0 allows a /v3/ec2tokens or /v3/s3tokens request with a valid AWS Signature to provide Keystone authorization.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/keystoneto a version that resolves this vulnerability.Fixed in 28.0.0 - Upgrade
Upgrade
pip/keystoneto a version that resolves this vulnerability.Fixed in 27.0.0 - Upgrade
Upgrade
pip/keystoneto a version that resolves this vulnerability.Fixed in 26.0.1
Event History
Frequently Asked Questions
What is the severity of CVE-2025-65073?
CVE-2025-65073 is considered to have a high severity due to its potential to allow unauthorized access to Keystone authorization.
How do I fix CVE-2025-65073?
To mitigate CVE-2025-65073, upgrade OpenStack Keystone to version 26.0.1 or later.
What are the affected versions of OpenStack Keystone in CVE-2025-65073?
CVE-2025-65073 affects OpenStack Keystone versions prior to 26.0.1, including all versions before 27.0.0 and 28.0.0.
What does CVE-2025-65073 exploit?
CVE-2025-65073 exploits the ability to make requests to /v3/ec2tokens or /v3/s3tokens for Keystone authorization using a valid AWS Signature.
What impact does CVE-2025-65073 have on OpenStack Keystone users?
CVE-2025-65073 allows potential unauthorized users to gain access to Keystone services, posing a significant security risk.