Source: keystone
Version: 2:29.0.1-2
Severity: grave
Tags: security upstream
Forwarded: https://launchpad.net/bugs/2154645
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerability was published for keystone.

CVE-2026-80183[0]:
| In OpenStack Keystone before 29.0.3, any authenticated user holding
| role:reader on any project can list every project-scoped role
| assignment under any domain by passing a domain ID as
| scope.project.id with include_subtree to the GET
| /v3/role_assignments endpoint. The domain's project record has
| domain_id=null, causing the policy domain_id check to pass for any
| caller. With include_names, the response discloses the names and
| home-domain IDs of every user, group, project, and role involved.
| The literal "default" domain ID works against any deployment created
| with keystone-manage bootstrap. An attacker can harvest domain IDs
| from the response and repeat the query to map role assignments
| across the entire cloud. This is caused by misuse of "None" inĀ 
| list_role_assignments_for_tree.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-80183
    https://www.cve.org/CVERecord?id=CVE-2026-80183
[1] https://launchpad.net/bugs/2154645

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

Reply via email to