#1149304 lp-2158970: POST /v3/users/{id}/password does not verify MFA when MFA rules are configured, allowing account lockout with stolen password alone #1149304
- Package:
- src:keystone
- Source:
- src:keystone
- Submitter:
- Thomas Goirand
- Date:
- 2026-10-02 09:01:02 UTC
- Severity:
- normal
- Tags:
As per launchpad bug at: https://bugs.launchpad.net/keystone/+bug/2158970 POST /v3/users/{user_id}/password (change password) is decorated @unenforced_api and requires only the user's original_password to succeed. When a user has MFA rules configured (e.g. requiring TOTP), this endpoint does not verify the additional factor. This violates the security guarantee MFA is intended to provide: a user who enables TOTP does so specifically because they expect their account to remain safe even if their password is stolen. For every other operation — login, API access, token issuance — that guarantee holds. For change_password it does not. Attack scenario: Precondition: victim has TOTP MFA rules configured. Attacker has obtained the victim's password (phishing, credential breach, etc.) but does not have access to the TOTP device. 1. Attacker cannot log in — TOTP gate blocks them. MFA is working as intended. 2. Attacker calls POST /v3/users/{user_id}/password with the stolen password, sets a new password the victim does not know. No token required (@unenforced_api), no TOTP required. 3. Victim's password is now unknown to them. They cannot log in. Their TOTP device is now useless — there is no second factor without the first. 4. Recovery requires admin intervention (PATCH /v3/users/{user_id} with admin token to reset the password). Root cause: identity.core.change_password calls only self.authenticate(user_id, original_password), a pure password check. MFA rules registered for the user are not consulted. There is no mechanism to require additional factors for this endpoint even when the user's account policy mandates them. Specification references: I was quick to dismiss this as a "hardening opportunity" when initially discussing this in bug 2157347 , but I was ignorant that the industry consensus is clear in this regard: • OWASP MFA Cheat Sheet: explicitly lists "Changing passwords" as a sensitive action for which MFA should be required alongside login • OWASP ASVS 7.5.1: "Verify that the application requires re-authentication before allowing modifications to sensitive account attributes which may affect authentication" • CWE-306: Missing Authentication for Critical Function • CWE-304: Missing Critical Step in Authentication: "The software implements an authentication technique, but it skips a crucial step that weakens the authentication." Suggested fix: Before executing the password change, check whether the user has active MFA rules. If so, require those factors to be satisfied — either via a valid session token that was issued meeting those factors, or by accepting the MFA factors inline in the same request body. A documented recovery path (admin-assisted password reset) should be provided for users who have lost their MFA device, replacing the current implicit bypass. Related: bug 2157347 (TOTP single-use not enforced — companion issue in the same MFA subsystem) Affected versions: All Keystone releases supporting per-user MFA rules, Stein (15.0.0) onwards.
Hello, Bug #1149304 in keystone reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/openstack-team/services/keystone/-/commit/78608aa89ca09127da29e6a7363928ceebdd266c ------------------------------------------------------------------------ * OSSN-0109: identity, credentials: require MFA re-verification for sensitive actions: - OSSN-0109_lp-2157347_invalidate_MFA_auth_receipts_and_TOTP_passco....patch (Closes: #1149305) - OSSN-0109_identity_credentials_require_MFA_re-verification_for_se....patch (Closes: #1149304) ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1149304
We believe that the bug you reported is fixed in the latest version of
keystone, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1149304@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Thomas Goirand <zigo@debian.org> (supplier of updated keystone package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Tue, 29 Sep 2026 12:33:16 +0200
Source: keystone
Architecture: source
Version: 2:30.0.0~rc1-2
Distribution: unstable
Urgency: medium
Maintainer: Debian OpenStack <team+openstack@tracker.debian.org>
Changed-By: Thomas Goirand <zigo@debian.org>
Closes: 1149304 1149305
Changes:
keystone (2:30.0.0~rc1-2) unstable; urgency=medium
.
* Add Type=notify to keystone service unit.
* OSSN-0109: identity, credentials: require MFA re-verification for
sensitive actions:
- OSSN-0109_lp-2157347_invalidate_MFA_auth_receipts_and_TOTP_passco....patch
(Closes: #1149305)
- OSSN-0109_identity_credentials_require_MFA_re-verification_for_se....patch
(Closes: #1149304)
Checksums-Sha1:
3e098755d3bc1e97b80bf726fea1a6bacc7d1d88 3486 keystone_30.0.0~rc1-2.dsc
7878d63215f687f9d25a6e1b01f7c19c9f896b3b 63956 keystone_30.0.0~rc1-2.debian.tar.xz
faa280d0214e2668b67bdd029e5c18fe8206c61e 17057 keystone_30.0.0~rc1-2_amd64.buildinfo
Checksums-Sha256:
7e399b271ff81f726268248bd5983b138d9b3a4aa50576e2a3983aa02267de8a 3486 keystone_30.0.0~rc1-2.dsc
e6d16e3ab6355f9d41d203de8dcca64b311745a55f543c80801df89988f2c8cb 63956 keystone_30.0.0~rc1-2.debian.tar.xz
e339bf4731eca20c9c8ac07651933eefc8f60b03fb606029f40a500d0b16f3fb 17057 keystone_30.0.0~rc1-2_amd64.buildinfo
Files:
a298cecf9e54263e312dd4080e8fe369 3486 net optional keystone_30.0.0~rc1-2.dsc
d9ef4444329f4868db641fbc2353d87e 63956 net optional keystone_30.0.0~rc1-2.debian.tar.xz
6683f4f8f0953dc6bab1dc6730505c3c 17057 net optional keystone_30.0.0~rc1-2_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEoLGp81CJVhMOekJc1BatFaxrQ/4FAmq7l1wACgkQ1BatFaxr
Q/424Q//Vc24oqTInOY+tAnrPgEAUdqhfiSZwVDepBrv3DTNiLMoJsRGxEQFFO4L
pxx4mWpdsK6Hdr0ypl8W8MHltMPC8erMJWxis5DMof5pjEV7OCCqpEOCROZSZugG
atnglQnToR0Y06p3iBi3+6pbxKrTJzTnXkpnN+7wG0UnPdv0rUd1pVSWdeZEplJV
fbewmDHYENxMCfMjLfQhvt30FAMSYBcN/gZ2C5QKSTLbU2DUBRtVhxsqJiPHx3qs
y4B9o8IkQXIrKNwm8sTjT6XcOts+Q559eOMy4eOnvX37XHeO3zefEPHxPaLXZcL8
hk3nIwv9uFmn38VTnoTj/dFu7koojR9TSVqNG0tIsY5rG55c+32a8jmBGKPzCSk7
jfTAHIHzJ6drYQF2pvlbvWqftK+PR+RTbjxLcCQR7L7YpxXcDb/eviJocedhEK2Y
ag75mhx2qHwT2d1i7vk203uK3UXJ2T7OcG4HFKXXDQATspP2xlqvbbRzRYN5pWho
+J2vO6VaObhLNNI8QKRwbPZLF+WckL8ytbvXVvYPsALEYAqWWavdzHxavipzafTW
i9PSlZvSUqtkZfvJGVndA7r1shwTGKxd4PKFMFMYBPLFQ/EAif+sL2M6+TpTPy+T
aAxGnuiAQBiwcaCmPeoJ2/GDlWYv+Lg5kZ+pjor23AAvfkKc2fo=
=x4dt
-----END PGP SIGNATURE-----