Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-65073

Опубликовано: 17 нояб. 2025
Источник: debian
EPSS Низкий

Описание

OpenStack Keystone before 26.0.1, 27.0.0, and 28.0.0 allows a /v3/ec2tokens or /v3/s3tokens request with a valid AWS Signature to provide Keystone authorization.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
keystonefixed2:28.0.0-2package

Примечания

  • https://www.openwall.com/lists/oss-security/2025/11/04/2

  • https://bugs.launchpad.net/keystone/+bug/2119646

  • src:swift (Bug #1120057) and src:heat (Bug #1120059) require updates along for

  • compatibility with the OSSA-2025-002/keystone update.

EPSS

Процентиль: 15%
0.00049
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
5 месяцев назад

OpenStack Keystone before 26.0.1, 27.0.0, and 28.0.0 allows a /v3/ec2tokens or /v3/s3tokens request with a valid AWS Signature to provide Keystone authorization.

CVSS3: 7.5
redhat
5 месяцев назад

OpenStack Keystone before 26.0.1, 27.0.0, and 28.0.0 allows a /v3/ec2tokens or /v3/s3tokens request with a valid AWS Signature to provide Keystone authorization.

CVSS3: 7.5
nvd
5 месяцев назад

OpenStack Keystone before 26.0.1, 27.0.0, and 28.0.0 allows a /v3/ec2tokens or /v3/s3tokens request with a valid AWS Signature to provide Keystone authorization.

CVSS3: 7.5
github
5 месяцев назад

OpenStack Keystone allows /v3/ec2tokens or /v3/s3tokens request with valid AWS Signature to provide Keystone authorization.

EPSS

Процентиль: 15%
0.00049
Низкий