oss-sec mailing list archives
Re: [OSSA-2025-002] OpenStack Keystone: Unauthenticated access to EC2/S3 token endpoints can grant Keystone authorization (CVE PENDING)
From: Jeremy Stanley <fungi () yuggoth org>
Date: Mon, 17 Nov 2025 15:19:50 +0000
On 2025-11-16 21:05:22 +0100 (+0100), Salvatore Bonaccorso wrote:
========================================================================= OSSA-2025-002: Unauthenticated access to EC2/S3 token endpoints can grant Keystone authorization =========================================================================[...]Notes ~~~~~[...]- MITRE CVE Request 1930434 has been awaiting assignment since 2025-09-24, but once completed will result in an errata revision to this advisory reflecting the correct CVE ID. If any other CNA has assigned a CVE themselves in the meantime, please reject it so that we don't end up with duplicates.Have you ever heard back since then for a CVE assignment? I guess it felt through the cracks?
The coordinator who initially filed request 1930434 in September followed up on the advisory publication date to let MITRE know it was now public and request they prioritize assigning a CVE, but as of the end of last week had still not heard back (I'll check in with him again today once it's daylight in his locale, but don't have high hopes the situation has changed).
We consider CVEs optional and don't hold up advisory publication for them, but will officially issue errata and post to this mailing list as soon as MITRE finally gets back to us. Thanks for checking in!
-- Jeremy Stanley on behalf of the OpenStack Vulnerability Management Team
Attachment:
signature.asc
Description:
Current thread:
- [OSSA-2025-002] OpenStack Keystone: Unauthenticated access to EC2/S3 token endpoints can grant Keystone authorization (CVE PENDING) Jeremy Stanley (Nov 04)
- Re: [OSSA-2025-002] OpenStack Keystone: Unauthenticated access to EC2/S3 token endpoints can grant Keystone authorization (CVE PENDING) Demi Marie Obenour (Nov 04)
- Re: [OSSA-2025-002] OpenStack Keystone: Unauthenticated access to EC2/S3 token endpoints can grant Keystone authorization (CVE PENDING) Salvatore Bonaccorso (Nov 16)
- Re: [OSSA-2025-002] OpenStack Keystone: Unauthenticated access to EC2/S3 token endpoints can grant Keystone authorization (CVE PENDING) Jeremy Stanley (Nov 17)
- [OSSA-2025-002] OpenStack Keystone: Unauthenticated access to EC2/S3 token endpoints can grant Keystone authorization (CVE-2025-65073) Jeremy Stanley (Nov 17)
