Source: keystone Version: 2:29.0.1-1 Severity: important Tags: security upstream Forwarded: https://bugs.launchpad.net/keystone/+bug/2149775 X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi, The following vulnerability was published for keystone. CVE-2026-43001[0]: | An issue was discovered in OpenStack Keystone 13 through 29. POST | /v3/credentials did not validate that the caller-supplied project_id | for an EC2-type credential matched the project of the authenticating | application credential. This allowed an attacker holding an | unrestricted application credential for project A to create an EC2 | credential targeting project B; a subsequent /v3/ec2tokens exchange | would then issue a Keystone token scoped to project B while still | carrying the original app_cred_id, enabling cross-project lateral | movement within the credential owner's role footprint. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-43001 https://www.cve.org/CVERecord?id=CVE-2026-43001 [1] https://bugs.launchpad.net/keystone/+bug/2149775 [2] https://review.opendev.org/c/openstack/keystone/+/985804 Please adjust the affected versions in the BTS as needed. Regards, Salvatore

