GHSA-whqr-fgm5-x77q

Suggest an improvement
Source
https://github.com/advisories/GHSA-whqr-fgm5-x77q
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-whqr-fgm5-x77q/GHSA-whqr-fgm5-x77q.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-whqr-fgm5-x77q
Aliases
Downstream
CGA (12)
Published
2026-05-28T21:32:02Z
Modified
2026-07-17T21:13:33Z
Severity
  • 6.0 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:L CVSS Calculator
Summary
OpenStack Keystone's federated token rescoping mechanism doesn't propagate the original token's expiry to the newly issued token
Details

An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone federated token rescoping mechanism does not propagate the original token's expiry to the newly issued token. When a federated user rescopes a token via POST /v3/auth/tokens, the handle_scoped_token() function in the mapped authentication plugin returns response data without an expires_at value. The token provider falls back to issuing a token with a fresh default TTL. By rescoping repeatedly before each token expires, a user can maintain access indefinitely, bypassing operator-configured token lifetime policies. This is a variant of CVE-2012-3426. Only deployments using federated identity (SAML2, OpenID Connect) are affected.

Database specific
{
    "cwe_ids": [
        "CWE-863"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-07-02T17:44:27Z",
    "nvd_published_at": "2026-05-28T19:16:38Z",
    "severity": "MODERATE"
}
References

Affected packages

PyPI / keystone

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
14.0.0
Fixed
27.0.2

Affected versions

14.*
14.0.0
14.0.1
14.1.0
14.2.0
15.*
15.0.0.0rc1
15.0.0.0rc2
15.0.0
15.0.1
16.*
16.0.0.0rc1
16.0.0.0rc2
16.0.0
16.0.1
16.0.2
17.*
17.0.0.0rc1
17.0.0.0rc2
17.0.0
17.0.1
18.*
18.0.0.0rc1
18.0.0
18.1.0
19.*
19.0.0.0rc1
19.0.0.0rc2
19.0.0
19.0.1
20.*
20.0.0.0rc1
20.0.0
20.0.1
21.*
21.0.0.0rc1
21.0.0
21.0.1
22.*
22.0.0.0rc1
22.0.0
22.0.1
22.0.2
23.*
23.0.0.0rc1
23.0.0
23.0.1
23.0.2
24.*
24.0.0.0rc1
24.0.0
24.1.0
25.*
25.0.0.0rc1
25.0.0
26.*
26.0.0.0rc1
26.0.0
26.1.0
26.1.1
27.*
27.0.0.0rc1
27.0.0
27.0.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-whqr-fgm5-x77q/GHSA-whqr-fgm5-x77q.json"

PyPI / keystone

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
28.0.0
Fixed
28.0.2

Affected versions

28.*
28.0.0
28.0.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-whqr-fgm5-x77q/GHSA-whqr-fgm5-x77q.json"

PyPI / keystone

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
29.0.0
Fixed
29.0.2

Affected versions

29.*
29.0.0
29.0.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-whqr-fgm5-x77q/GHSA-whqr-fgm5-x77q.json"