TEMP-1149304-59264A

NameTEMP-1149304-59264A
DescriptionPOST /v3/users/{id}/password does not verify MFA when MFA rules are configured, allowing account lockout with stolen password alone
SourceAutomatically generated temporary name. Not for external reference.
Debian Bugs1149304

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
keystone (PTS)bookworm2:22.0.2-0+deb12u3vulnerable
bookworm (security)2:22.0.2-0+deb12u4vulnerable
trixie (security), trixie2:27.0.0-3+deb13u5vulnerable
forky, sid2:30.0.0-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
keystonesource(unstable)2:30.0.0~rc1-21149304

Notes

[trixie] - keystone <no-dsa> (Minor issue)
https://bugs.launchpad.net/keystone/+bug/2158970

Search for package or bug name: Reporting problems