The vendor explicitly identifies these products as affected by this CVE.
- rhosp13/openstack-keystone as a component of Red Hat OpenStack Platform 13 (Queens)
- rhosp-rhel9/openstack-keystone as a component of Red Hat OpenStack Platform 17.1
- rhoso/openstack-keystone-rhel9 as a component of Red Hat OpenStack Platform 18.0
- Summary
- A flaw was found in OpenStack Keystone. This vulnerability allows an attacker to obtain a valid OpenStack's Keystone token, leading to access to unauthorized resources or privilege escalation within the OpenStack instance via sending a valid AWS (Amazon Web Services) signature to the /v3/ec2tokens or /v3/s3tokens API (Application Programming Interface) endpoints.
- Remediation
- Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258
