Skip to main content

Vendor/product archive

openstack / keystone CVEs

Beta · best-effort

44 CVEs tagged to openstack / keystone0 Critical, 11 High, 30 Medium, 3 Low, 0 Unrated.

CVE-2026-44394

Published May 28, 2026

An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone federated token rescoping mechanism does not propagate the original token's expiry to the newly issued to…

CVSS 6.0 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-43000

Published May 28, 2026

An issue was discovered in OpenStack Keystone before 29.0.2. When combined with an application credential impersonation vulnerability, an attacker with the member role on a projec…

CVSS 6.0 · Medium
evidence mentions
5
Buzz score
32.4
Vendor/product tagsBeta · best-effort

CVE-2026-42999

Published May 28, 2026

An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone RBAC policy enforcer in enforce_call unconditionally merges the raw JSON request body into the policy enf…

CVSS 6.0 · Medium
evidence mentions
5
Buzz score
32.4
Vendor/product tagsBeta · best-effort

CVE-2026-42998

Published May 28, 2026

An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone application credential authentication plugin does not verify that the user supplied in the authentication…

CVSS 6.0 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-43001

Published May 1, 2026

An issue was discovered in OpenStack Keystone before 29.0.2. POST /v3/credentials did not validate that the caller-supplied project_id for an EC2-type credential matched the proje…

CVSS 7.9 · High
evidence mentions
7
Buzz score
40.3
Vendor/product tagsBeta · best-effort

CVE-2026-33551

Published Apr 10, 2026

An issue was discovered in OpenStack Keystone 14 through 26 before 26.1.1, 27.0.0, 28.0.0, and 29.0.0. Restricted application credentials can create EC2 credentials. By using a re…

CVSS 3.5 · Low
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2021-38155

Published Aug 6, 2021

OpenStack Keystone 10.x through 16.x before 16.0.2, 17.x before 17.0.1, 18.x before 18.0.1, and 19.x before 19.0.1 allows information disclosure during account locking (related to…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-12690

Published May 7, 2020

An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. The list of roles provided for an OAuth1 access token is silently ignored. Thus, when an access token is u…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-19687

Published Dec 9, 2019

OpenStack Keystone 15.0.0 and 16.0.0 is affected by Data Leakage in the list credentials API. Any user with a role on a project is able to list any credentials with the /v3/creden…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-20170

Published Dec 17, 2018

OpenStack Keystone through 14.0.1 has a user enumeration vulnerability because invalid usernames have much faster responses than valid ones for a POST /v3/auth/tokens request. NOT…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-3646

Published May 12, 2015

OpenStack Identity (Keystone) before 2014.1.5 and 2014.2.x before 2014.2.4 logs the backend_argument configuration option content, which allows remote authenticated users to obtai…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0204

Published Nov 3, 2014

OpenStack Identity (Keystone) before 2014.1.1 does not properly handle when a role is assigned to a group that has the same ID as a user, which allows remote authenticated users t…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-3520

Published Oct 26, 2014

OpenStack Identity (Keystone) before 2013.2.4, 2014.x before 2014.1.2, and Juno before Juno-2 allows remote authenticated trustees to gain access to an unauthorized project for wh…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-5253

Published Aug 25, 2014

OpenStack Identity (Keystone) 2014.1.x before 2014.1.2.1 and Juno before Juno-3 does not properly revoke tokens when a domain is invalidated, which allows remote authenticated use…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-5252

Published Aug 25, 2014

The V3 API in OpenStack Identity (Keystone) 2014.1.x before 2014.1.2.1 and Juno before Juno-3 updates the issued_at value for UUID v2 tokens, which allows remote authenticated use…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 44 CVEsPage 1 of 2