REDHAT-BUG-2451037: Low severity Openstack Keystone vulnerability
Maxence Bornecque from Orange Cyberdefense CERT Vulnerability Intelligence Watch Team reported a vulnerability in Keystone's EC2 credential creation endpoint. By using a restricted application credential to call the EC2 credential creation API, an authenticated user with only a reader role may obtain an EC2/S3 credential that carries the full set of the parent user's S3 permissions, effectively bypassing the role restrictions imposed on the application credential. Only deployments that use restricted application credentials in combination with the EC2/S3 compatibility API (swift3 / s3api) are affected.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2451037?
The severity of REDHAT-BUG-2451037 is classified as low.
How do I fix REDHAT-BUG-2451037?
To remediate REDHAT-BUG-2451037, restrict access to the EC2 credential creation endpoint by adjusting user roles and permissions.
What software is affected by REDHAT-BUG-2451037?
The vulnerability REDHAT-BUG-2451037 affects OpenStack Keystone.
Who reported REDHAT-BUG-2451037?
REDHAT-BUG-2451037 was reported by Maxence Bornecque from the Orange Cyberdefense CERT Vulnerability Intelligence Watch Team.
What is the description of REDHAT-BUG-2451037?
REDHAT-BUG-2451037 concerns a vulnerability that allows an authenticated user with a reader role to exploit the EC2 credential creation API using a restricted application credential.