Published: 11 Dec 2025, 14:24
Last modified:27 Apr 2026, 18:31

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

11 Dec 2025, 14:24
Published
Vulnerability first disclosed
27 Apr 2026, 18:31
Last Modified
Vulnerability information updated

Description

keystone vulnerabilities Kay discovered that OpenStack Keystone incorrectly handled the ec2tokens and s3tokens APIs. A remote attacker could possibly use this issue to obtain unauthorized access and escalate privileges. (CVE-2025-65073) It was discovered that OpenStack Keystone only validated the first 72 bytes of an application secret. An attacker could possibly use this issue to bypass password complexity. (CVE-2021-3563) It was discovered that OpenStack Keystone had a time lag before a token should be revoked by the security policy. A remote administrator could use this issue to maintain access for longer than expected. (CVE-2022-2447)

Affected Systems

  • ubuntukeystone

    < 2:21.0.1-0ubuntu2.1

References (4)