Описание
An issue was discovered in OpenStack Keystone before 29.0.2. When combined with an application credential impersonation vulnerability, an attacker with the member role on a project can escalate to admin by chaining unrestricted application credentials with Keystone trusts. The impersonated token carries the victim's identity, which passes the trustor validation check. Keystone then validates the delegated roles against the victim's actual role assignments in the database, not the roles on the requesting token. This allows the attacker to create a trust delegating the victim's admin role to themselves. The trust persists independently, and additional trusts and application credentials can be created to maintain access. All actions are logged under the victim's identity.
A flaw was found in OpenStack Keystone. An attacker with a member role on a project can escalate their privileges to an administrator role. This is achieved by combining an application credential impersonation vulnerability with the misuse of Keystone trusts. The system incorrectly validates delegated roles against the victim's actual database roles instead of the requesting token, allowing the attacker to create a trust that grants them the victim's administrative privileges. This trust can then be used to maintain persistent access.
Отчет
This IMPORTANT privilege escalation in Keystone allows project members to gain admin access by chaining application credential impersonation with trust exploitation. High complexity is required (multiple vulnerability chain). The scope is changed as the attacker gains persistent admin access affecting other users. Impact is high to confidentiality and integrity. Affects versions before 29.0.2.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat OpenStack Platform 13 (Queens) | rhosp13/openstack-keystone | Affected | ||
| Red Hat OpenStack Platform 16.2 | openstack-keystone | Affected | ||
| Red Hat OpenStack Platform 16.2 | rhosp-rhel8/openstack-keystone | Affected | ||
| Red Hat OpenStack Platform 17.1 | openstack-keystone | Affected | ||
| Red Hat OpenStack Platform 17.1 | rhosp-rhel9/openstack-keystone | Affected | ||
| Red Hat OpenStack Platform 18.0 | openstack-keystone | Affected | ||
| Red Hat OpenStack Platform 18.0 | rhoso/openstack-keystone-rhel9 | Affected |
Показывать по
Дополнительная информация
Статус:
EPSS
8.4 High
CVSS3
Связанные уязвимости
An issue was discovered in OpenStack Keystone before 29.0.2. When combined with an application credential impersonation vulnerability, an attacker with the member role on a project can escalate to admin by chaining unrestricted application credentials with Keystone trusts. The impersonated token carries the victim's identity, which passes the trustor validation check. Keystone then validates the delegated roles against the victim's actual role assignments in the database, not the roles on the requesting token. This allows the attacker to create a trust delegating the victim's admin role to themselves. The trust persists independently, and additional trusts and application credentials can be created to maintain access. All actions are logged under the victim's identity.
An issue was discovered in OpenStack Keystone before 29.0.2. When combined with an application credential impersonation vulnerability, an attacker with the member role on a project can escalate to admin by chaining unrestricted application credentials with Keystone trusts. The impersonated token carries the victim's identity, which passes the trustor validation check. Keystone then validates the delegated roles against the victim's actual role assignments in the database, not the roles on the requesting token. This allows the attacker to create a trust delegating the victim's admin role to themselves. The trust persists independently, and additional trusts and application credentials can be created to maintain access. All actions are logged under the victim's identity.
An issue was discovered in OpenStack Keystone before 29.0.2. When comb ...
OpenStack Keystone has an Incorrect Authorization issue
EPSS
8.4 High
CVSS3