Descrição
An issue was discovered in OpenStack Keystone before 29.0.2. When combined with an application credential impersonation vulnerability, an attacker with the member role on a project can escalate to admin by chaining unrestricted application credentials with Keystone trusts. The impersonated token carries the victim-s identity, which passes the trustor validation check. Keystone then validates the delegated roles against the victim-s actual role assignments in the database, not the roles on the requesting token. This allows the attacker to create a trust delegating the victim-s admin role to themselves. The trust persists independently, and additional trusts and application credentials can be created to maintain access. All actions are logged under the victim-s identity.
- Publicação
- 2026-05-28 19:16:37
- Versões afetadas
- <29.0.2
- Tipo
- Core software
- Última alteração
- 2026-07-23 12:18:03
- Vetor
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:L