← Späť na vyhľadávanie CVE

CVE-2026-33551

OpenStack Keystone

Popis

An issue was discovered in OpenStack Keystone 14 through 26 before 26.1.1, 27.0.0, 28.0.0, and 29.0.0. Restricted application credentials can create EC2 credentials. By using a restricted application credential to call the EC2 credential creation API, an authenticated user with only a reader role may obtain an EC2/S3 credential that carries the full set of the parent user-s S3 permissions, effectively bypassing the role restrictions imposed on the application credential. Only deployments that use restricted application credentials in combination with the EC2/S3 compatibility API (swift3 / s3api) are affected.

CVSS 3.5EPSS 0.22%Riziko 0.36
Zobraziť zdroj
Zverejnené
2026-04-10 03:16:02
Dotknuté verzie
<26.1.1, <27.0.0, <28.0.0, <29.0.0
Typ
Core software
Vektor
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:N