oss-sec mailing list archives

Re: [OSSA-2025-002] OpenStack Keystone: Unauthenticated access to EC2/S3 token endpoints can grant Keystone authorization (CVE PENDING)


From: Jeremy Stanley <fungi () yuggoth org>
Date: Mon, 17 Nov 2025 15:19:50 +0000

On 2025-11-16 21:05:22 +0100 (+0100), Salvatore Bonaccorso wrote:
=========================================================================
OSSA-2025-002: Unauthenticated access to EC2/S3 token endpoints can grant
               Keystone authorization
=========================================================================
[...]
Notes
~~~~~
[...]
- MITRE CVE Request 1930434 has been awaiting assignment since
  2025-09-24, but once completed will result in an errata revision to
  this advisory reflecting the correct CVE ID. If any other CNA has
  assigned a CVE themselves in the meantime, please reject it so that we
  don't end up with duplicates.

Have you ever heard back since then for a CVE assignment? I guess it felt through the cracks?

The coordinator who initially filed request 1930434 in September followed up on the advisory publication date to let MITRE know it was now public and request they prioritize assigning a CVE, but as of the end of last week had still not heard back (I'll check in with him again today once it's daylight in his locale, but don't have high hopes the situation has changed).

We consider CVEs optional and don't hold up advisory publication for them, but will officially issue errata and post to this mailing list as soon as MITRE finally gets back to us. Thanks for checking in!
--
Jeremy Stanley
on behalf of the OpenStack Vulnerability Management Team

Attachment: signature.asc
Description:


Current thread: