DEBIAN-CVE-2025-65073

Source
https://security-tracker.debian.org/tracker/CVE-2025-65073
Import Source
https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-65073.json
JSON Data
https://api.test.osv.dev/v1/vulns/DEBIAN-CVE-2025-65073
Upstream
  • CVE-2025-65073
Published
2025-11-17T08:16:25.600Z
Modified
2025-11-18T11:15:39.946790Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:N CVSS Calculator
Summary
[none]
Details

OpenStack Keystone before 26.0.1, 27.0.0, and 28.0.0 allows a /v3/ec2tokens or /v3/s3tokens request with a valid AWS Signature to provide Keystone authorization.

References

Affected packages

Debian:11 / keystone

Package

Name
keystone
Purl
pkg:deb/debian/keystone?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2:18.1.0-1+deb11u2

Affected versions

2:18.*

2:18.0.0-3
2:18.0.0-3+deb11u1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / keystone

Package

Name
keystone
Purl
pkg:deb/debian/keystone?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2:22.0.2-0+deb12u1

Affected versions

2:22.*

2:22.0.0-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / keystone

Package

Name
keystone
Purl
pkg:deb/debian/keystone?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2:27.0.0-3+deb13u1

Affected versions

2:27.*

2:27.0.0-3

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:14 / keystone

Package

Name
keystone
Purl
pkg:deb/debian/keystone?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2:28.0.0-2

Affected versions

2:27.*

2:27.0.0-3

2:28.*

2:28.0.0~rc1-1
2:28.0.0~rc1-2
2:28.0.0~rc1-4
2:28.0.0-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}