GHSA-q623-f4j4-p4xj

Suggest an improvement
Source
https://github.com/advisories/GHSA-q623-f4j4-p4xj
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-q623-f4j4-p4xj/GHSA-q623-f4j4-p4xj.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-q623-f4j4-p4xj
Aliases
Downstream
CGA (12)
Published
2026-05-28T21:32:02Z
Modified
2026-07-17T21:07:02Z
Severity
  • 6.0 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:L CVSS Calculator
Summary
OpenStack Keystone has an Incorrect Authorization issue
Details

An issue was discovered in OpenStack Keystone before 29.0.2. When combined with an application credential impersonation vulnerability, an attacker with the member role on a project can escalate to admin by chaining unrestricted application credentials with Keystone trusts. The impersonated token carries the victim's identity, which passes the trustor validation check. Keystone then validates the delegated roles against the victim's actual role assignments in the database, not the roles on the requesting token. This allows the attacker to create a trust delegating the victim's admin role to themselves. The trust persists independently, and additional trusts and application credentials can be created to maintain access. All actions are logged under the victim's identity.

Database specific
{
    "cwe_ids": [
        "CWE-266",
        "CWE-863"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-07-02T17:44:16Z",
    "nvd_published_at": "2026-05-28T19:16:37Z",
    "severity": "MODERATE"
}
References

Affected packages

PyPI / keystone

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
14.0.0
Fixed
27.0.2

Affected versions

14.*
14.0.0
14.0.1
14.1.0
14.2.0
15.*
15.0.0.0rc1
15.0.0.0rc2
15.0.0
15.0.1
16.*
16.0.0.0rc1
16.0.0.0rc2
16.0.0
16.0.1
16.0.2
17.*
17.0.0.0rc1
17.0.0.0rc2
17.0.0
17.0.1
18.*
18.0.0.0rc1
18.0.0
18.1.0
19.*
19.0.0.0rc1
19.0.0.0rc2
19.0.0
19.0.1
20.*
20.0.0.0rc1
20.0.0
20.0.1
21.*
21.0.0.0rc1
21.0.0
21.0.1
22.*
22.0.0.0rc1
22.0.0
22.0.1
22.0.2
23.*
23.0.0.0rc1
23.0.0
23.0.1
23.0.2
24.*
24.0.0.0rc1
24.0.0
24.1.0
25.*
25.0.0.0rc1
25.0.0
26.*
26.0.0.0rc1
26.0.0
26.1.0
26.1.1
27.*
27.0.0.0rc1
27.0.0
27.0.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-q623-f4j4-p4xj/GHSA-q623-f4j4-p4xj.json"

PyPI / keystone

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
28.0.0
Fixed
28.0.2

Affected versions

28.*
28.0.0
28.0.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-q623-f4j4-p4xj/GHSA-q623-f4j4-p4xj.json"

PyPI / keystone

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
29.0.0
Fixed
29.0.2

Affected versions

29.*
29.0.0
29.0.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-q623-f4j4-p4xj/GHSA-q623-f4j4-p4xj.json"