OpenStack / Keystone
44 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-90460 | An issue was discovered in OpenStack Keystone before 29.0.3. Tokens obtained via delegated authentication methods (EC2 credentials, application credentials, OA… | HIGH | 7.6 | Sep 11, 2026 |
| CVE-2026-80183 | keystone: OpenStack Keystone: Information disclosure via improper handling of domain IDs in role assignment listings | HIGH | 7.1 | Aug 26, 2026 |
| CVE-2026-80184 | keystone: keystone: Application credential tokens can escape project scope via token-method reauthentication | HIGH | 7.6 | Aug 25, 2026 |
| CVE-2026-80182 | keystone: keystone: Delegated token scope restrictions not consistently enforced across trust, OAuth1, and application credential endpoints | HIGH | 7.6 | Aug 25, 2026 |
| CVE-2026-44394 | openstack-keystone: OpenStack Keystone: Federated token rescoping allows indefinite access | HIGH | 8.1 | May 28, 2026 |
| CVE-2026-43000 | keystone: OpenStack Keystone: Privilege escalation via chained application credential impersonation and trust misuse | HIGH | 8.8 | May 28, 2026 |
| CVE-2026-42999 | openstack-keystone: OpenStack Keystone: Unauthorized access and privilege escalation via arbitrary policy attribute injection | HIGH | 8.8 | May 28, 2026 |
| CVE-2026-42998 | openstack-keystone: OpenStack Keystone: User impersonation and unauthorized access via insufficient application credential verification. | HIGH | 8.8 | May 28, 2026 |
| CVE-2026-43001 | OpenStack Keystone: OpenStack Keystone: Unauthorized cross-project access due to improper validation in EC2 credential creation | HIGH | 8.0 | May 1, 2026 |
| CVE-2026-40683 | OpenStack Keystone: OpenStack Keystone: Unauthorized access due to incorrect LDAP user status handling | HIGH | 7.7 | Apr 14, 2026 |
| CVE-2026-33551 | openstack-keystone: OpenStack Keystone: Privilege escalation through EC2 credential creation | MEDIUM | 5.3 | Apr 10, 2026 |
| CVE-2025-65073 | openstack-keystone: OpenStack Keystone: Unauthorized access and privilege escalation via AWS signature validation flaw | HIGH | 7.5 | Nov 17, 2025 |
| CVE-2022-2447 | Openstack: Application credential token remains valid longer than expected | MEDIUM | 6.6 | Sep 1, 2022 |
| CVE-2021-3563 | Keystone: Verification of application credentials is silently length-limited | CRITICAL | 9.1 | Aug 26, 2022 |
| CVE-2021-38155 | OpenStack Keystone 10.x through 16.x before 16.0.2, 17.x before 17.0.1, 18.x before 18.0.1, and 19.x before 19.0.1 allows information disclosure during account… | HIGH | 7.5 | Aug 6, 2021 |
| CVE-2020-12689 | openstack-keystone: EC2 and credential endpoints are not protected from a scoped context | HIGH | 8.7 | May 6, 2020 |
| CVE-2020-12690 | openstack-keystone: OAuth1 request token authorize silently ignores roles parameter | HIGH | 8.7 | May 6, 2020 |
| CVE-2020-12691 | openstack-keystone: Credentials endpoint policy logic allows changing credential owner and target project ID | HIGH | 8.7 | May 6, 2020 |
| CVE-2020-12692 | openstack-keystone: failure to check signature TTL of the EC2 credential auth method | MEDIUM | 5.3 | May 6, 2020 |
| CVE-2019-19687 | openstack-keystone: Credentials API allows non-admin to list and retrieve all users credentials | HIGH | 8.7 | Dec 9, 2019 |
| CVE-2012-1572 | OpenStack Keystone: extremely long passwords can crash Keystone by exhausting stack space | HIGH | 7.5 | Nov 12, 2019 |
| CVE-2013-2255 | openstack-*: Inconsistent and non-validating HTTPS client | MEDIUM | 5.9 | Nov 1, 2019 |
| CVE-2018-20170 | OpenStack Keystone through 14.0.1 has a user enumeration vulnerability because invalid usernames have much faster responses than valid ones for a POST /v3/auth… | MEDIUM | 5.3 | Dec 17, 2018 |
| CVE-2018-14432 | openstack-keystone: Information Exposure through /v3/OS-FEDERATION/projects | MEDIUM | 5.3 | Jul 31, 2018 |
| CVE-2015-7546 | openstack-keystone: Improper check of tampered revocated PKI/PKIZ token | HIGH | 8.6 | Feb 3, 2016 |
Showing 1 to 25 of 44 CVEs