TEMP-1120053-9E7D6D

NameTEMP-1120053-9E7D6D
DescriptionOSSA-2025-002: Unauthenticated access to EC2/S3 token endpoints can grant Keystone authorization
SourceAutomatically generated temporary name. Not for external reference.
Debian Bugs1120053

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
keystone (PTS)bullseye2:18.0.0-3+deb11u1vulnerable
bookworm2:22.0.0-2vulnerable
trixie2:27.0.0-3vulnerable
forky, sid2:28.0.0-1vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
keystonesource(unstable)(unfixed)1120053

Notes

https://www.openwall.com/lists/oss-security/2025/11/04/2
https://bugs.launchpad.net/keystone/+bug/2119646
src:swift (Bug #1120057) and src:heat (Bug #1120059) require updates along for
compatibility with the OSSA-2025-002/keystone update.

Search for package or bug name: Reporting problems