USN-7926-1
Advisory lineage Upstream: 6 Downstream: 0
Published: 11 Dec 2025, 14:24
Last modified:27 Apr 2026, 18:31
Vulnerability Summary
Overall Risk (default)
minimal
0/100 CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
11 Dec 2025, 14:24
Published
Vulnerability first disclosed
27 Apr 2026, 18:31
Last Modified
Vulnerability information updated
Description
keystone vulnerabilities Kay discovered that OpenStack Keystone incorrectly handled the ec2tokens and s3tokens APIs. A remote attacker could possibly use this issue to obtain unauthorized access and escalate privileges. (CVE-2025-65073) It was discovered that OpenStack Keystone only validated the first 72 bytes of an application secret. An attacker could possibly use this issue to bypass password complexity. (CVE-2021-3563) It was discovered that OpenStack Keystone had a time lag before a token should be revoked by the security policy. A remote administrator could use this issue to maintain access for longer than expected. (CVE-2022-2447)
Affected Systems
- ubuntu•keystone
< 2:21.0.1-0ubuntu2.1