Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-42999

Опубликовано: 28 мая 2026
Источник: redhat
CVSS3: 8.3
EPSS Низкий

Описание

An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone RBAC policy enforcer in enforce_call unconditionally merges the raw JSON request body into the policy enforcement dictionary via policy_dict.update(json_input.copy()), overwriting trusted target data that was previously set from database lookups. Because flask.request.get_json is called with force=True, this works regardless of Content-Type or HTTP method. Any authenticated user can inject arbitrary policy target attributes (e.g., user_id, project_id) into the request body to bypass RBAC checks and perform unauthorized operations on resources belonging to other users or projects. This was introduced in commit 5ea59f52 (Rocky/14.0.0).

A flaw was found in OpenStack Keystone. This vulnerability allows an authenticated user to bypass Role-Based Access Control (RBAC) checks by injecting arbitrary policy target attributes into the request body. This enables the user to perform unauthorized operations on resources belonging to other users or projects. The issue stems from the Keystone RBAC policy enforcer unconditionally merging the raw JSON request body into its policy enforcement dictionary, which overwrites trusted data.

Отчет

This IMPORTANT RBAC bypass vulnerability in Keystone allows authenticated users to inject policy attributes and access other users' resources. Exploitation is straightforward—just include target IDs in the request body. Impact is high to confidentiality and integrity. The scope is unchanged as the attack remains within Keystone's authorization domain. Affects versions since Rocky/14.0.0, fixed in 29.0.2.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenStack Platform 13 (Queens)rhosp13/openstack-keystoneAffected
Red Hat OpenStack Platform 16.2openstack-keystoneAffected
Red Hat OpenStack Platform 16.2rhosp-rhel8/openstack-keystoneAffected
Red Hat OpenStack Platform 17.1openstack-keystoneAffected
Red Hat OpenStack Platform 17.1rhosp-rhel9/openstack-keystoneAffected
Red Hat OpenStack Platform 18.0openstack-keystoneAffected
Red Hat OpenStack Platform 18.0rhoso/openstack-keystone-rhel9Affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-639
https://bugzilla.redhat.com/show_bug.cgi?id=2482840openstack-keystone: OpenStack Keystone: Unauthorized access and privilege escalation via arbitrary policy attribute injection

EPSS

Процентиль: 25%
0.00329
Низкий

8.3 High

CVSS3

Связанные уязвимости

CVSS3: 6
ubuntu
2 месяца назад

An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone RBAC policy enforcer in enforce_call unconditionally merges the raw JSON request body into the policy enforcement dictionary via policy_dict.update(json_input.copy()), overwriting trusted target data that was previously set from database lookups. Because flask.request.get_json is called with force=True, this works regardless of Content-Type or HTTP method. Any authenticated user can inject arbitrary policy target attributes (e.g., user_id, project_id) into the request body to bypass RBAC checks and perform unauthorized operations on resources belonging to other users or projects. This was introduced in commit 5ea59f52 (Rocky/14.0.0).

CVSS3: 6
nvd
2 месяца назад

An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone RBAC policy enforcer in enforce_call unconditionally merges the raw JSON request body into the policy enforcement dictionary via policy_dict.update(json_input.copy()), overwriting trusted target data that was previously set from database lookups. Because flask.request.get_json is called with force=True, this works regardless of Content-Type or HTTP method. Any authenticated user can inject arbitrary policy target attributes (e.g., user_id, project_id) into the request body to bypass RBAC checks and perform unauthorized operations on resources belonging to other users or projects. This was introduced in commit 5ea59f52 (Rocky/14.0.0).

CVSS3: 6
debian
2 месяца назад

An issue was discovered in OpenStack Keystone before 29.0.2. The Keyst ...

CVSS3: 6
github
2 месяца назад

OpenStack Keystone has an Authorization Bypass

EPSS

Процентиль: 25%
0.00329
Низкий

8.3 High

CVSS3