#1149303 lp-2159643: Delegated tokens (like ec2credential, application_credential, ...) can GET/PATCH/DELETE any credential including TOTP seeds (CVE-2026-pending) #1149303
- Package:
- src:keystone
- Source:
- src:keystone
- Submitter:
- Thomas Goirand
- Date:
- 2026-10-09 13:47:04 UTC
- Severity:
- normal
- Tags:
Copying launchpad.net bug from: https://bugs.launchpad.net/keystone/+bug/2159643 Tokens obtained via delegated authentication methods (ec2credential, application_credential) can call PATCH /v3/credentials and DELETE /v3/credentials/{id} on any credential owned by the same user, regardless of credential type. This allows a holder of an ec2 access/secret key pair (or an application credential) to: • Overwrite a TOTP seed (type=totp) — immediately invalidates the user's authenticator app and substitutes the attacker's seed, bypassing MFA • Read credentials: • ec2credential token can Read TOTP seed — full silent MFA compromise (as well as any other credential blobs) • application_credential token is correctly blocked from GET on individual credentials (403), but can still list all ec2 credentials (one API call dumps all credentials with their complete secrets) • Change the project_id of any ec2 credential — re-scopes the credential to any other project the user has roles in, escalating the access the key provides. (A holder of an ec2 access/secret key pair can use the token obtained from that key to change the project_id of that same credential, re-scoping it to any other project the user has roles in.) • Delete TOTP, SSH, or other credential types — credential wipe/DoS • Create new credentials of any type via POST /v3/credentials (also unblocked for ec2credential tokens — see bug 2153453 for the related CREATE gap) Steps to reproduce (PATCH TOTP seed via ec2credential token): 1. User creates an ec2 credential and a TOTP credential 2. Attacker obtains the ec2 access/secret keys (e.g., from a shared server) 3. Attacker calls POST /v3/ec2tokens (via a service account) to obtain an ec2credential token 4. Attacker calls PATCH /v3/credentials/{totp_cred_id} with the new TOTP seed using that token → 200 OK 5. User's authenticator app is now invalid; attacker controls the MFA seed Steps to reproduce (project_id scope escalation): 1. User has ec2 credential scoped to Project A (member), and also has admin role in Project B 2. Attacker obtains the ec2 access/secret 3. Attacker gets ec2credential token, calls PATCH /v3/credentials/{ec2_cred_id} with {"project_id": "<project_B_id>", "blob": "..."} 4. Next ec2tokens call returns a token scoped to Project B with admin role Root cause: credentials.py patch() and delete() handlers have no guard against delegated token methods. post() has a partial guard (_check_unrestricted_application_credential) that bug 2153453 is extending, but patch() and delete() have no equivalent. The _validate_blob_update_keys guard only fires for existing ec2-type credentials and only validates blob key stability, not the token method. Proposed fix: Add a _require_primary_auth guard to POST, PATCH, and DELETE in credentials.py (and users.py OS-EC2 endpoint) that blocks any token whose methods list contains no primary authentication method: _PRIMARY_METHODS = frozenset({'password', 'totp', 'mapped', 'token'}) def _require_primary_auth_for_credential_write(token): if not _PRIMARY_METHODS.intersection(token.methods): raise exception.ForbiddenAction( action=_("Modifying credentials requires primary " "authentication (password, totp, or mapped).") ) This covers ec2credential, application_credential, oauth1, and trust tokens by default, and any future delegated method without needing per-type guards. It also handles third-party custom credential types. Note: This is the tip of the iceberg. EC2-derived tokens and application credential tokens produce fully-privileged project-scoped Keystone tokens usable against any OpenStack service API. Nova's keypair API (POST/DELETE /v2/{project_id}/os-keypairs) has the same structural exposure — a stolen ec2 key can add attacker-controlled SSH keypairs to a project. This behavior is undocumented -- one might assume that EC2 tokens work only on EC2/S3 APIs. Nova and other services do not introspect token methods; enforcement there would require a broader cross-project effort. Note2: Type is a free-form string, no validation or whitelist. Any auth plugin, integration, or third-party service can store credentials under custom types. So any restrictions might interfere with legitimate, custom usage. Severity: High Affects: All Keystone versions with ec2credentials enabled Related: bug 2153453 (credential creation via delegated tokens), bug 2158970 (Adding/removing TOTP credentials requires no MFA re-auth)
Hello, Bug #1149303 in keystone reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/keystone/-/commit/40ae58a630b2cf274971c5755456e91f2e80920f ------------------------------------------------------------------------ * CVE-2026-XXXXX / OSSA-2026-0XXX: Delegated tokens (like ec2credential, application_credential, ...) can GET/PATCH/DELETE any credential including TOTP seeds. Delegation project boundary not enforced on PATCH /v3/credentials/{id}. This was due to an incomplete fix for OSSA-2026-015. Applied upstream patch: "credentials: reject delegated tokens, restrict PATCH to blob only" (Closes: #1149303): - CVE-2026-XXXXX_lp-2159643_credentials_reject_delegated-tokens_re....patch * OSSN-0109: identity, credentials: require MFA re-verification for sensitive actions: - OSSN-0109_lp-2157347_invalidate_MFA_auth_receipts_and_TOTP_passco....patch (Closes: #1149305) - OSSN-0109_lp-2158970_identity_credentials_require_MFA_re-verifica....patch (Closes: #1149304) ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1149303
Hello, Bug #1149303 in keystone reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/keystone/-/commit/9e47b8967080f38cf66484fea866a9dbaff3b429 ------------------------------------------------------------------------ * CVE-2026-XXXXX / OSSA-2026-0XXX: Delegated tokens (like ec2credential, application_credential, ...) can GET/PATCH/DELETE any credential including TOTP seeds. Delegation project boundary not enforced on PATCH /v3/credentials/{id}. This was due to an incomplete fix for OSSA-2026-015. Applied upstream patch: "credentials: reject delegated tokens, restrict PATCH to blob only" (Closes: #1149303): - CVE-2026-XXXXX_lp-2159643_credentials_reject_delegated-tokens_re....patch ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1149303
Hello, Bug #1149303 in keystone reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/keystone/-/commit/1d676e1ec150b5611439b7abe234cca74b3a1385 ------------------------------------------------------------------------ * CVE-2026-XXXXX / OSSA-2026-0XXX: Delegated tokens (like ec2credential, application_credential, ...) can GET/PATCH/DELETE any credential including TOTP seeds. Delegation project boundary not enforced on PATCH /v3/credentials/{id}. This was due to an incomplete fix for OSSA-2026-015. Applied upstream patch: "credentials: reject delegated tokens, restrict PATCH to blob only" (Closes: #1149303): - CVE-2026-XXXXX_lp-2159643_credentials_reject_delegated-tokens_re....patch * OSSN-0109: identity, credentials: require MFA re-verification for sensitive actions: - OSSN-0109_lp-2157347_invalidate_MFA_auth_receipts_and_TOTP_passco....patch (Closes: #1149305) - OSSN-0109_lp-2158970_identity_credentials_require_MFA_re-verifica....patch (Closes: #1149304) ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1149303
Hello, Bug #1149303 in keystone reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/keystone/-/commit/3322860de03f4c5b4ab327d2e6f25351ade14aaa ------------------------------------------------------------------------ * CVE-2026-XXXXX / OSSA-2026-0XXX: Delegated tokens (like ec2credential, application_credential, ...) can GET/PATCH/DELETE any credential including TOTP seeds. Delegation project boundary not enforced on PATCH /v3/credentials/{id}. This was due to an incomplete fix for OSSA-2026-015. Applied upstream patch: "credentials: reject delegated tokens, restrict PATCH to blob only" (Closes: #1149303): - CVE-2026-XXXXX_lp-2159643_credentials_reject_delegated-tokens_re....patch * OSSN-0109: identity, credentials: require MFA re-verification for sensitive actions: - OSSN-0109_lp-2157347_invalidate_MFA_auth_receipts_and_TOTP_passco....patch (Closes: #1149305) - OSSN-0109_lp-2158970_identity_credentials_require_MFA_re-verifica....patch (Closes: #1149304) ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1149303
Hello, Bug #1149303 in keystone reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/keystone/-/commit/c490f55c8aedbc968e908d8f206c1584d68799eb ------------------------------------------------------------------------ * CVE-2026-XXXXX / OSSA-2026-0XXX: Delegated tokens (like ec2credential, application_credential, ...) can GET/PATCH/DELETE any credential including TOTP seeds. Delegation project boundary not enforced on PATCH /v3/credentials/{id}. This was due to an incomplete fix for OSSA-2026-015. Applied upstream patch: "credentials: reject delegated tokens, restrict PATCH to blob only" (Closes: #1149303): - CVE-2026-XXXXX_lp-2159643_credentials_reject_delegated-tokens_re....patch * OSSN-0109: identity, credentials: require MFA re-verification for sensitive actions: - OSSN-0109_lp-2157347_invalidate_MFA_auth_receipts_and_TOTP_passco....patch (Closes: #1149305) - OSSN-0109_lp-2158970_identity_credentials_require_MFA_re-verifica....patch (Closes: #1149304) ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1149303
Hello, Bug #1149303 in keystone reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/keystone/-/commit/e9afb0589401d6bbb4cf56913db2072c0dc6531b ------------------------------------------------------------------------ * CVE-2026-XXXXX / OSSA-2026-0XXX: Delegated tokens (like ec2credential, application_credential, ...) can GET/PATCH/DELETE any credential including TOTP seeds. Delegation project boundary not enforced on PATCH /v3/credentials/{id}. This was due to an incomplete fix for OSSA-2026-015. Applied upstream patch: "credentials: reject delegated tokens, restrict PATCH to blob only" (Closes: #1149303): - CVE-2026-XXXXX_lp-2159643_credentials_reject_delegated-tokens_re....patch * OSSN-0109: identity, credentials: require MFA re-verification for sensitive actions: - OSSN-0109_lp-2157347_invalidate_MFA_auth_receipts_and_TOTP_passco....patch (Closes: #1149305) - OSSN-0109_lp-2158970_identity_credentials_require_MFA_re-verifica....patch (Closes: #1149304) ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1149303
Hello, Bug #1149303 in keystone reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/keystone/-/commit/24aa6b68cca86b4b463a7c944f36d7f6324b11da ------------------------------------------------------------------------ * CVE-2026-XXXXX / OSSA-2026-0XXX: Delegated tokens (like ec2credential, application_credential, ...) can GET/PATCH/DELETE any credential including TOTP seeds. Delegation project boundary not enforced on PATCH /v3/credentials/{id}. This was due to an incomplete fix for OSSA-2026-015. Applied upstream patch: "credentials: reject delegated tokens, restrict PATCH to blob only" (Closes: #1149303): - CVE-2026-XXXXX_lp-2159643_credentials_reject_delegated-tokens_re....patch * OSSN-0109: identity, credentials: require MFA re-verification for sensitive actions: - OSSN-0109_lp-2157347_invalidate_MFA_auth_receipts_and_TOTP_passco....patch (Closes: #1149305) - OSSN-0109_lp-2158970_identity_credentials_require_MFA_re-verifica....patch (Closes: #1149304) ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1149303
Hello, Bug #1149303 in keystone reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/keystone/-/commit/a73e4663460f625de8ec12828b8e3738cf0c104f ------------------------------------------------------------------------ * CVE-2026-XXXXX / OSSA-2026-0XXX: Delegated tokens (like ec2credential, application_credential, ...) can GET/PATCH/DELETE any credential including TOTP seeds. Delegation project boundary not enforced on PATCH /v3/credentials/{id}. This was due to an incomplete fix for OSSA-2026-015. Applied upstream patch: "credentials: reject delegated tokens, restrict PATCH to blob only" (Closes: #1149303): - CVE-2026-XXXXX_lp-2159643_credentials_reject_delegated-tokens_re....patch * OSSN-0109: identity, credentials: require MFA re-verification for sensitive actions: - OSSN-0109_lp-2157347_invalidate_MFA_auth_receipts_and_TOTP_passco....patch (Closes: #1149305) - OSSN-0109_lp-2158970_identity_credentials_require_MFA_re-verifica....patch (Closes: #1149304) ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1149303
Hello, Bug #1149303 in keystone reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/keystone/-/commit/76a8e111c49f4f36211455ccc8c35bd7ccbfe2a1 ------------------------------------------------------------------------ * CVE-2026-XXXXX / OSSA-2026-0XXX: Delegated tokens (like ec2credential, application_credential, ...) can GET/PATCH/DELETE any credential including TOTP seeds. Delegation project boundary not enforced on PATCH /v3/credentials/{id}. This was due to an incomplete fix for OSSA-2026-015. Applied upstream patch: "credentials: reject delegated tokens, restrict PATCH to blob only" (Closes: #1149303): - CVE-2026-XXXXX_lp-2159643_credentials_reject_delegated-tokens_re....patch * OSSN-0109: identity, credentials: require MFA re-verification for sensitive actions: - OSSN-0109_lp-2157347_invalidate_MFA_auth_receipts_and_TOTP_passco....patch (Closes: #1149305) - OSSN-0109_lp-2158970_identity_credentials_require_MFA_re-verifica....patch (Closes: #1149304) ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1149303
Hello, Bug #1149303 in keystone reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/keystone/-/commit/72cc3300325e7b1e15942f0c4a17d4ed270b9ab5 ------------------------------------------------------------------------ * CVE-2026-XXXXX / OSSA-2026-0XXX: Delegated tokens (like ec2credential, application_credential, ...) can GET/PATCH/DELETE any credential including TOTP seeds. Delegation project boundary not enforced on PATCH /v3/credentials/{id}. This was due to an incomplete fix for OSSA-2026-015. Applied upstream patch: "credentials: reject delegated tokens, restrict PATCH to blob only" (Closes: #1149303): - CVE-2026-XXXXX_lp-2159643_credentials_reject_delegated-tokens_re....patch * OSSN-0109: identity, credentials: require MFA re-verification for sensitive actions: - OSSN-0109_lp-2157347_invalidate_MFA_auth_receipts_and_TOTP_passco....patch (Closes: #1149305) - OSSN-0109_lp-2158970_identity_credentials_require_MFA_re-verifica....patch (Closes: #1149304) ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1149303
Hello, Bug #1149303 in keystone reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/keystone/-/commit/a93a8c3c5c2cd6950599e38a9f5349c624f3c8f2 ------------------------------------------------------------------------ * CVE-2026-XXXXX / OSSA-2026-0XXX: Delegated tokens (like ec2credential, application_credential, ...) can GET/PATCH/DELETE any credential including TOTP seeds. Delegation project boundary not enforced on PATCH /v3/credentials/{id}. This was due to an incomplete fix for OSSA-2026-015. Applied upstream patch: "credentials: reject delegated tokens, restrict PATCH to blob only" (Closes: #1149303): - CVE-2026-XXXXX_lp-2159643_credentials_reject_delegated-tokens_re....patch * OSSN-0109: identity, credentials: require MFA re-verification for sensitive actions: - OSSN-0109_lp-2157347_invalidate_MFA_auth_receipts_and_TOTP_passco....patch (Closes: #1149305) - OSSN-0109_lp-2158970_identity_credentials_require_MFA_re-verifica....patch (Closes: #1149304) ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1149303
Hello, Bug #1149303 in keystone reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/keystone/-/commit/85bbb4c7040c63894e8a7f8f5bc476d817566596 ------------------------------------------------------------------------ * CVE-2026-XXXXX / OSSA-2026-0XXX: Delegated tokens (like ec2credential, application_credential, ...) can GET/PATCH/DELETE any credential including TOTP seeds. Delegation project boundary not enforced on PATCH /v3/credentials/{id}. This was due to an incomplete fix for OSSA-2026-015. Applied upstream patch: "credentials: reject delegated tokens, restrict PATCH to blob only" (Closes: #1149303): - CVE-2026-XXXXX_lp-2159643_credentials_reject_delegated-tokens_re....patch * OSSN-0109: identity, credentials: require MFA re-verification for sensitive actions: - OSSN-0109_lp-2157347_invalidate_MFA_auth_receipts_and_TOTP_passco....patch (Closes: #1149305) - OSSN-0109_lp-2158970_identity_credentials_require_MFA_re-verifica....patch (Closes: #1149304) ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1149303
Hello, Bug #1149303 in keystone reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/keystone/-/commit/5fecf2bc8b997380055a1c46a905bd34a2633132 ------------------------------------------------------------------------ * CVE-2026-XXXXX / OSSA-2026-0XXX: Delegated tokens (like ec2credential, application_credential, ...) can GET/PATCH/DELETE any credential including TOTP seeds. Delegation project boundary not enforced on PATCH /v3/credentials/{id}. This was due to an incomplete fix for OSSA-2026-015. Applied upstream patch: "credentials: reject delegated tokens, restrict PATCH to blob only" (Closes: #1149303): - CVE-2026-XXXXX_lp-2159643_credentials_reject_delegated-tokens_re....patch * OSSN-0109: identity, credentials: require MFA re-verification for sensitive actions: - OSSN-0109_lp-2157347_invalidate_MFA_auth_receipts_and_TOTP_passco....patch (Closes: #1149305) - OSSN-0109_lp-2158970_identity_credentials_require_MFA_re-verifica....patch (Closes: #1149304) ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1149303
Hello, Bug #1149303 in keystone reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/keystone/-/commit/cd8a399a1a15b3f15ea21a868322ed7e8b143581 ------------------------------------------------------------------------ * CVE-2026-XXXXX / OSSA-2026-0XXX: Delegated tokens (like ec2credential, application_credential, ...) can GET/PATCH/DELETE any credential including TOTP seeds. Delegation project boundary not enforced on PATCH /v3/credentials/{id}. This was due to an incomplete fix for OSSA-2026-015. Applied upstream patch: "credentials: reject delegated tokens, restrict PATCH to blob only" (Closes: #1149303): - CVE-2026-XXXXX_lp-2159643_credentials_reject_delegated-tokens_re....patch * OSSN-0109: identity, credentials: require MFA re-verification for sensitive actions: - OSSN-0109_lp-2157347_invalidate_MFA_auth_receipts_and_TOTP_passco....patch (Closes: #1149305) - OSSN-0109_lp-2158970_identity_credentials_require_MFA_re-verifica....patch (Closes: #1149304) ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1149303
Hello, Bug #1149303 in keystone reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/keystone/-/commit/112b6899466c6561aa84fc38a5d10944885cf1db ------------------------------------------------------------------------ * CVE-2026-90460: Delegated tokens (like ec2credential, application_credential, ...) can GET/PATCH/DELETE any credential including TOTP seeds. Delegation project boundary not enforced on PATCH /v3/credentials/{id}. This was due to an incomplete fix for OSSA-2026-015. Applied upstream patch: "credentials: reject delegated tokens, restrict PATCH to blob only" (Closes: #1149303, #1149956): - CVE-2026-90460_lp-2159643_credentials_reject_delegated-tokens_re....patch ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1149303
Hello, Bug #1149303 in keystone reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/keystone/-/commit/7ac5b82d27fd45cf7a7f37dfccb8f27176c207f2 ------------------------------------------------------------------------ * CVE-2026-90460: Delegated tokens (like ec2credential, application_credential, ...) can GET/PATCH/DELETE any credential including TOTP seeds. Delegation project boundary not enforced on PATCH /v3/credentials/{id}. This was due to an incomplete fix for OSSA-2026-015. Applied upstream patch: "credentials: reject delegated tokens, restrict PATCH to blob only" (Closes: #1149303, #1149956): - CVE-2026-90460_lp-2159643_credentials_reject_delegated-tokens_re....patch * OSSN-0109: identity, credentials: require MFA re-verification for sensitive actions: - OSSN-0109_lp-2157347_invalidate_MFA_auth_receipts_and_TOTP_passco....patch (Closes: #1149305) - OSSN-0109_lp-2158970_identity_credentials_require_MFA_re-verifica....patch (Closes: #1149304) ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1149303
Hello, Bug #1149303 in keystone reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/keystone/-/commit/321ff5fec6779ed52961ba706680ba7838ae4531 ------------------------------------------------------------------------ * CVE-2026-90460: Delegated tokens (like ec2credential, application_credential, ...) can GET/PATCH/DELETE any credential including TOTP seeds. Delegation project boundary not enforced on PATCH /v3/credentials/{id}. This was due to an incomplete fix for OSSA-2026-015. Applied upstream patch: "credentials: reject delegated tokens, restrict PATCH to blob only" (Closes: #1149303, #1149956): - CVE-2026-90460_lp-2159643_credentials_reject_delegated-tokens_re....patch * OSSN-0109: identity, credentials: require MFA re-verification for sensitive actions: - OSSN-0109_lp-2157347_invalidate_MFA_auth_receipts_and_TOTP_passco....patch (Closes: #1149305) - OSSN-0109_lp-2158970_identity_credentials_require_MFA_re-verifica....patch (Closes: #1149304) ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1149303
Hello, Bug #1149303 in keystone reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/keystone/-/commit/1498872d0da59e74c92b4b42ac35269c7ff8c9e5 ------------------------------------------------------------------------ * CVE-2026-90460: Delegated tokens (like ec2credential, application_credential, ...) can GET/PATCH/DELETE any credential including TOTP seeds. Delegation project boundary not enforced on PATCH /v3/credentials/{id}. This was due to an incomplete fix for OSSA-2026-015. Applied upstream patch: "credentials: reject delegated tokens, restrict PATCH to blob only" (Closes: #1149303, #1149956): - CVE-2026-90460_lp-2159643_credentials_reject_delegated-tokens_re....patch * OSSN-0109: identity, credentials: require MFA re-verification for sensitive actions: - OSSN-0109_lp-2157347_invalidate_MFA_auth_receipts_and_TOTP_passco....patch (Closes: #1149305) - OSSN-0109_lp-2158970_identity_credentials_require_MFA_re-verifica....patch (Closes: #1149304) ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1149303
Hello, Bug #1149303 in keystone reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/keystone/-/commit/50c195201478d0cff46b7ea0667ee07973fc749e ------------------------------------------------------------------------ * CVE-2026-90460: Delegated tokens (like ec2credential, application_credential, ...) can GET/PATCH/DELETE any credential including TOTP seeds. Delegation project boundary not enforced on PATCH /v3/credentials/{id}. This was due to an incomplete fix for OSSA-2026-015. Applied upstream patch: "credentials: reject delegated tokens, restrict PATCH to blob only" (Closes: #1149303, #1149956): - CVE-2026-90460_lp-2159643_credentials_reject_delegated-tokens_re....patch * OSSN-0109: identity, credentials: require MFA re-verification for sensitive actions: - OSSN-0109_lp-2157347_invalidate_MFA_auth_receipts_and_TOTP_passco....patch (Closes: #1149305) - OSSN-0109_lp-2158970_identity_credentials_require_MFA_re-verifica....patch (Closes: #1149304) ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1149303
Hello, Bug #1149303 in keystone reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/keystone/-/commit/98e9818252d062c5e7cd3d133f8d39618d6264c4 ------------------------------------------------------------------------ * CVE-2026-90460: Delegated tokens (like ec2credential, application_credential, ...) can GET/PATCH/DELETE any credential including TOTP seeds. Delegation project boundary not enforced on PATCH /v3/credentials/{id}. This was due to an incomplete fix for OSSA-2026-015. Applied upstream patch: "credentials: reject delegated tokens, restrict PATCH to blob only" (Closes: #1149303, #1149956): - CVE-2026-90460_lp-2159643_credentials_reject_delegated-tokens_re....patch * OSSN-0109: identity, credentials: require MFA re-verification for sensitive actions: - OSSN-0109_lp-2157347_invalidate_MFA_auth_receipts_and_TOTP_passco....patch (Closes: #1149305) - OSSN-0109_lp-2158970_identity_credentials_require_MFA_re-verifica....patch (Closes: #1149304) ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1149303
Hello, Bug #1149303 in keystone reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/keystone/-/commit/1232f36b5f9d25dcaaa9c49c1da4ae60f4dba7e3 ------------------------------------------------------------------------ * CVE-2026-90460: Delegated tokens (like ec2credential, application_credential, ...) can GET/PATCH/DELETE any credential including TOTP seeds. Delegation project boundary not enforced on PATCH /v3/credentials/{id}. This was due to an incomplete fix for OSSA-2026-015. Applied upstream patch: "credentials: reject delegated tokens, restrict PATCH to blob only" (Closes: #1149303, #1149956): - CVE-2026-90460_lp-2159643_credentials_reject_delegated-tokens_re....patch * OSSN-0109: identity, credentials: require MFA re-verification for sensitive actions: - OSSN-0109_lp-2157347_invalidate_MFA_auth_receipts_and_TOTP_passco....patch (Closes: #1149305) - OSSN-0109_lp-2158970_identity_credentials_require_MFA_re-verifica....patch (Closes: #1149304) ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1149303
Hello, Bug #1149303 in keystone reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/keystone/-/commit/1a465a9a3438c87dff0e85ccdd421f675ed3a272 ------------------------------------------------------------------------ * CVE-2026-90460: Delegated tokens (like ec2credential, application_credential, ...) can GET/PATCH/DELETE any credential including TOTP seeds. Delegation project boundary not enforced on PATCH /v3/credentials/{id}. This was due to an incomplete fix for OSSA-2026-015. Applied upstream patch: "credentials: reject delegated tokens, restrict PATCH to blob only" (Closes: #1149303, #1149956): - CVE-2026-90460_lp-2159643_credentials_reject_delegated-tokens_re....patch * OSSN-0109: identity, credentials: require MFA re-verification for sensitive actions: - OSSN-0109_lp-2157347_invalidate_MFA_auth_receipts_and_TOTP_passco....patch (Closes: #1149305) - OSSN-0109_lp-2158970_identity_credentials_require_MFA_re-verifica....patch (Closes: #1149304) ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1149303
Hello, Bug #1149303 in keystone reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/keystone/-/commit/6edca0332d93309d1b9ecd2c6a569987c13cb2c4 ------------------------------------------------------------------------ CVE-2026-90460: Delegated tokens (like ec2credential, application_credential, ...) can GET/PATCH/DELETE any credential including TOTP seeds. Delegation project boundary not enforced on PATCH /v3/credentials/{id}. Applied upstream patch: "credentials: reject delegated tokens, restrict PATCH to blob only" (Closes: #1149303, #1149956): - CVE-2026-90460_lp-2159643_credentials_reject_delegated-tokens_re....patch ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1149303
Hello, Bug #1149303 in keystone reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/keystone/-/commit/6f94605929491d13ed73c35cd121f675d7a4d7bb ------------------------------------------------------------------------ CVE-2026-90460: Delegated tokens (like ec2credential, application_credential, ...) can GET/PATCH/DELETE any credential including TOTP seeds. Delegation project boundary not enforced on PATCH /v3/credentials/{id}. Applied upstream patch: "credentials: reject delegated tokens, restrict PATCH to blob only" (Closes: #1149303, #1149956): - CVE-2026-90460_lp-2159643_credentials_reject_delegated-tokens_re....patch ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1149303