TEMP-1149303-26B919

NameTEMP-1149303-26B919
DescriptionDelegated tokens (like ec2credential, application_credential, ...) can GET/PATCH/DELETE any credential including TOTP seeds
SourceAutomatically generated temporary name. Not for external reference.
Debian Bugs1149303

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
keystone (PTS)bookworm2:22.0.2-0+deb12u3vulnerable
bookworm (security)2:22.0.2-0+deb12u4vulnerable
trixie (security), trixie2:27.0.0-3+deb13u5vulnerable
forky, sid2:30.0.0-1vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
keystonesource(unstable)(unfixed)1149303

Notes

[trixie] - keystone <no-dsa> (Minor issue)
https://bugs.launchpad.net/keystone/+bug/2159643

Search for package or bug name: Reporting problems