VDB
KO
CRITICAL 9.1

GHSA-cc99-whm5-mmq3

Openstack Keystone Incorrect Authorization vulnerability

Details

A flaw was found in openstack-keystone, only the first 72 characters of an application secret are verified allowing attackers bypass some password complexity which administrators may be counting on. The highest threat from this vulnerability is to data confidentiality and integrity. A [patch](https://opendev.org/openstack/keystone/commit/7859ed26003858ebfd9a5e866b43f1a6a9e83dca) is available.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI / keystone
Introduced in: 0

No fixed version published yet for keystone (pip). Pin to a known-safe version or switch to an alternative.

References