Source: keystone Version: 2:29.0.1-2 Severity: grave Tags: security upstream Forwarded: https://launchpad.net/bugs/2154645 X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi, The following vulnerability was published for keystone. CVE-2026-80183[0]: | In OpenStack Keystone before 29.0.3, any authenticated user holding | role:reader on any project can list every project-scoped role | assignment under any domain by passing a domain ID as | scope.project.id with include_subtree to the GET | /v3/role_assignments endpoint. The domain's project record has | domain_id=null, causing the policy domain_id check to pass for any | caller. With include_names, the response discloses the names and | home-domain IDs of every user, group, project, and role involved. | The literal "default" domain ID works against any deployment created | with keystone-manage bootstrap. An attacker can harvest domain IDs | from the response and repeat the query to map role assignments | across the entire cloud. This is caused by misuse of "None" inĀ | list_role_assignments_for_tree. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-80183 https://www.cve.org/CVERecord?id=CVE-2026-80183 [1] https://launchpad.net/bugs/2154645 Please adjust the affected versions in the BTS as needed. Regards, Salvatore

