Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-42998

Опубликовано: 28 мая 2026
Источник: redhat
CVSS3: 4.9
EPSS Низкий

Описание

An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone application credential authentication plugin does not verify that the user supplied in the authentication request matches the owner of the application credential. An attacker can authenticate with their own application credential ID and secret while specifying a different user's name and domain in the request body. Keystone issues a token attributed to the victim user. The impersonated token is project-scoped and carries the intersection of the application credential's roles and the victim's actual roles on the project. This enables audit evasion, reading the victim's credentials, and acting as the victim within shared projects.

A flaw was found in OpenStack Keystone. The application credential authentication plugin fails to verify if the user provided in an authentication request matches the owner of the application credential. This allows a remote attacker to authenticate with their own credentials while impersonating another user, gaining unauthorized access to project-scoped resources and potentially evading audits. The attacker can read the victim's credentials and act as the victim within shared projects.

Отчет

This MODERATE impersonation vulnerability in Keystone's application credential plugin allows authenticated users to obtain tokens attributed to other users. Exploitation requires high complexity (valid app credentials and shared project context). Impact is limited to the intersection of attacker's app credential roles and victim's actual project roles. Affects versions before 29.0.2.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenStack Platform 13 (Queens)rhosp13/openstack-keystoneFix deferred
Red Hat OpenStack Platform 16.2openstack-keystoneFix deferred
Red Hat OpenStack Platform 16.2rhosp-rhel8/openstack-keystoneFix deferred
Red Hat OpenStack Platform 17.1openstack-keystoneFix deferred
Red Hat OpenStack Platform 17.1rhosp-rhel9/openstack-keystoneFix deferred
Red Hat OpenStack Platform 18.0openstack-keystoneFix deferred
Red Hat OpenStack Platform 18.0rhoso/openstack-keystone-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-303
https://bugzilla.redhat.com/show_bug.cgi?id=2482825openstack-keystone: OpenStack Keystone: User impersonation and unauthorized access via insufficient application credential verification.

EPSS

Процентиль: 22%
0.00303
Низкий

4.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 6
ubuntu
2 месяца назад

An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone application credential authentication plugin does not verify that the user supplied in the authentication request matches the owner of the application credential. An attacker can authenticate with their own application credential ID and secret while specifying a different user's name and domain in the request body. Keystone issues a token attributed to the victim user. The impersonated token is project-scoped and carries the intersection of the application credential's roles and the victim's actual roles on the project. This enables audit evasion, reading the victim's credentials, and acting as the victim within shared projects.

CVSS3: 6
nvd
2 месяца назад

An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone application credential authentication plugin does not verify that the user supplied in the authentication request matches the owner of the application credential. An attacker can authenticate with their own application credential ID and secret while specifying a different user's name and domain in the request body. Keystone issues a token attributed to the victim user. The impersonated token is project-scoped and carries the intersection of the application credential's roles and the victim's actual roles on the project. This enables audit evasion, reading the victim's credentials, and acting as the victim within shared projects.

CVSS3: 6
debian
2 месяца назад

An issue was discovered in OpenStack Keystone before 29.0.2. The Keyst ...

CVSS3: 6
github
2 месяца назад

OpenStack Keystone doesn't verify that the user supplied in the authentication request matches the owner of the application credential

EPSS

Процентиль: 22%
0.00303
Низкий

4.9 Medium

CVSS3