Control: tag -1 pending

Hello,

Bug #1145816 in keystone reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/services/keystone/-/commit/80537ae6c1b980eb368a661b3a5d34dab3f7c814

------------------------------------------------------------------------
* CVE-2026-80183 / OSSN-2026-0XXX: any authenticated user holding role:reader
    on any project can list every project-scoped role assignment under any
    domain by passing a domain ID as scope.project.id with include_subtree to
    the GET /v3/role_assignments endpoint. The domain's project record has
    domain_id=null, causing the policy domain_id check to pass for any caller.
    With include_names, the response discloses the names and home-domain IDs of
    every user, group, project, and role involved. The literal "default" domain
    ID works against any deployment created with keystone-manage bootstrap. An
    attacker can harvest domain IDs from the response and repeat the query to
    map role assignments across the entire cloud. This is caused by misuse of
    "None" in list_role_assignments_for_tree.
    Applied upstream patch (Closes: #1145816):
    - CVE-2026-80183_Prevent_unauthorized_project-scoped_assignment_list.patch
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1145816

Reply via email to