REDHAT-BUG-2464305: High severity Openstack Keystone vulnerability
An issue was discovered in OpenStack Keystone 13 through 29. POST /v3/credentials did not validate that the caller-supplied projectid for an EC2-type credential matched the project of the authenticating application credential. This allowed an attacker holding an unrestricted application credential for project A to create an EC2 credential targeting project B; a subsequent /v3/ec2tokens exchange would then issue a Keystone token scoped to project B while still carrying the original appcredid, enabling cross-project lateral movement within the credential owner's role footprint.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2464305?
The severity of REDHAT-BUG-2464305 is rated as high with a score of 7.
How do I fix REDHAT-BUG-2464305?
To fix REDHAT-BUG-2464305, ensure that proper validation is implemented for the project_id of EC2-type credentials in OpenStack Keystone.
What software is affected by REDHAT-BUG-2464305?
The software affected by REDHAT-BUG-2464305 is OpenStack Keystone versions 13 through 29.
What vulnerability does REDHAT-BUG-2464305 describe?
REDHAT-BUG-2464305 describes a vulnerability where the project_id validation is not enforced for EC2-type credentials in OpenStack Keystone.
What potential impact does REDHAT-BUG-2464305 have?
The potential impact of REDHAT-BUG-2464305 is that an attacker with unrestricted application credentials could exploit the flaw to gain unauthorized access.