Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-43001

Опубликовано: 01 мая 2026
Источник: nvd
CVSS3: 7.9
CVSS3: 8
EPSS Низкий

Описание

An issue was discovered in OpenStack Keystone before 29.0.2. POST /v3/credentials did not validate that the caller-supplied project_id for an EC2-type credential matched the project of the authenticating application credential. This allowed an attacker holding an unrestricted application credential for project A to create an EC2 credential targeting project B; a subsequent /v3/ec2tokens exchange would then issue a Keystone token scoped to project B while still carrying the original app_cred_id, enabling cross-project lateral movement within the credential owner's role footprint.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:openstack:keystone:*:*:*:*:*:*:*:*
Версия от 14.0.0 (включая) до 27.0.2 (исключая)
cpe:2.3:a:openstack:keystone:*:*:*:*:*:*:*:*
Версия от 28.0.0 (включая) до 28.0.2 (исключая)
cpe:2.3:a:openstack:keystone:*:*:*:*:*:*:*:*
Версия от 29.0.0 (включая) до 29.0.2 (исключая)

EPSS

Процентиль: 37%
0.00456
Низкий

7.9 High

CVSS3

8 High

CVSS3

Дефекты

CWE-863
CWE-1288

Связанные уязвимости

CVSS3: 7.9
ubuntu
3 месяца назад

An issue was discovered in OpenStack Keystone before 29.0.2. POST /v3/credentials did not validate that the caller-supplied project_id for an EC2-type credential matched the project of the authenticating application credential. This allowed an attacker holding an unrestricted application credential for project A to create an EC2 credential targeting project B; a subsequent /v3/ec2tokens exchange would then issue a Keystone token scoped to project B while still carrying the original app_cred_id, enabling cross-project lateral movement within the credential owner's role footprint.

CVSS3: 8
redhat
3 месяца назад

An issue was discovered in OpenStack Keystone before 29.0.2. POST /v3/credentials did not validate that the caller-supplied project_id for an EC2-type credential matched the project of the authenticating application credential. This allowed an attacker holding an unrestricted application credential for project A to create an EC2 credential targeting project B; a subsequent /v3/ec2tokens exchange would then issue a Keystone token scoped to project B while still carrying the original app_cred_id, enabling cross-project lateral movement within the credential owner's role footprint.

CVSS3: 7.9
debian
3 месяца назад

An issue was discovered in OpenStack Keystone before 29.0.2. POST /v3/ ...

CVSS3: 7.9
github
3 месяца назад

OpenStack Keystone has an Incorrect Authorization Issue

EPSS

Процентиль: 37%
0.00456
Низкий

7.9 High

CVSS3

8 High

CVSS3

Дефекты

CWE-863
CWE-1288