Skip to content

Add OSSA-2026-037 security advisory for Keystone - #1075

Merged
berendt merged 1 commit into
mainfrom
ossa-2026-037
Aug 25, 2026
Merged

Add OSSA-2026-037 security advisory for Keystone#1075
berendt merged 1 commit into
mainfrom
ossa-2026-037

Conversation

@berendt

@berendt berendt commented Aug 25, 2026

Copy link
Copy Markdown
Member

Documents the inconsistent scope enforcement for delegated tokens in Keystone
(OSSA-2026-037,
LP #2153453,
LP #2158538; two CVE ids requested from MITRE, still pending).

Tokens derived from EC2 credentials and OAuth1 access tokens could create trusts, application
credentials and OAuth1 access tokens that outlive the original credential — and, because trust
creation validates roles against the trustor's full assignments, carry roles the delegation never
had. Application credential tokens presented without a scope were rescoped to the owner's default
project, and EC2-derived tokens could be rescoped to any project of the user via the token
authentication method.

Every OSISM deployment is affected: application credentials, EC2 credentials, trusts and the token
method are available by default and allow_rescope_scoped_token defaults to True. Exploitation
requires possession of a delegated credential.

No fixed Keystone release exists upstream yet; all eight reviews
(10023011002308) are
still open. OSISM ships the proposed patches for 2025.1 and 2025.2 via
container-images-kolla PR #776; the
2026.1 patches are included but those images are not published yet. Community-curated backports
for 2024.1 and 2024.2 are in preparation; the page says so and announces an update.

The remediation overrides keystone_tag together with keystone_image, keystone_fernet_image
and keystone_ssh_image, because a stable OSISM release pulls from the
kolla/release/<openstack_version> namespace while the rolling images live in kolla
(see osism/defaults all/002-images-kolla.yml).

Points worth a second look:

  • The patched images additionally carry the master-only change Ban ec2credential tokens from
    Keystone API
    (997369, [auth] ban_ec2credential_tokens,
    default True). Documented as a behavior change in its own section.
  • The check for a patched image imports keystone.api._shared.delegation via
    /var/lib/kolla/venv/bin/python3 inside the keystone container — not tested against a live
    image yet.
  • Severity High is OSISM's own assessment (no CVSS published).

Follow-ups once available: CVE ids, PR/commit of the 2024.x backports, upstream fix versions
27.0.3 / 28.0.3 / 29.0.3.

Assisted-by: Claude:claude-fable-5

🤖 Generated with Claude Code

@github-actions

github-actions Bot commented Aug 25, 2026

Copy link
Copy Markdown

⚠️MegaLinter analysis: Success with warnings

Descriptor Linter Files Fixed Errors Max errors Warnings Elapsed time
✅ ACTION actionlint 5 0 0 0.07s
✅ JSON jsonlint 4 0 0 0.09s
✅ JSON prettier 4 0 0 0.33s
✅ JSON v8r 4 0 0 9.98s
✅ MARKDOWN markdownlint 169 0 0 2.3s
✅ MARKDOWN markdown-table-formatter 169 0 0 0.35s
✅ REPOSITORY betterleaks yes no no 0.61s
✅ REPOSITORY checkov yes no no 18.14s
✅ REPOSITORY git_diff yes no no 0.07s
✅ REPOSITORY secretlint yes no no 3.17s
✅ REPOSITORY trufflehog yes no no 3.98s
✅ SPELL codespell 179 0 0 0.65s
⚠️ SPELL lychee 179 21 0 38.64s
✅ YAML prettier 6 0 0 0.35s
✅ YAML v8r 6 0 0 6.55s
✅ YAML yamllint 6 0 0 0.51s

Detailed Issues

⚠️ SPELL / lychee - 21 errors
📝 Summary
---------------------
🔍 Total.........1068
🔗 Unique.........818
✅ Successful.....970
⏳ Timeouts.........6
🔀 Redirected.......5
👻 Excluded........71
❓ Unknown..........0
🚫 Errors..........21
⛔ Unsupported.....21

Errors in docs/concepts/cluster-network.md
[TIMEOUT] https://stordis.com/basic-configuration-and-management-of-sonic-devices/ (at 196:3) | Request timed out
[TIMEOUT] https://stordis.com/bgp-unnumbered-in-enterprise-sonic/ (at 66:1) | Request timed out
[TIMEOUT] https://stordis.com/deploying-bgp-underlay-in-enterprise-sonic/ (at 197:3) | Request timed out

Errors in docs/guides/deploy-guide/metalbox.md
[503] https://nbg1.your-objectstorage.com/osism/metalbox/octavia-export-2025.1.img (at 137:4) | Rejected status code: 503 Service Unavailable
[503] https://nbg1.your-objectstorage.com/osism/metalbox/octavia-export-2025.1.img (at 430:4) | Rejected status code: 503 Service Unavailable
[503] https://nbg1.your-objectstorage.com/osism/metalbox/registry-2025.1-full.tar.bz2 (at 132:4) | Rejected status code: 503 Service Unavailable
[503] https://nbg1.your-objectstorage.com/osism/metalbox/registry-2025.1-full.tar.bz2 (at 415:4) | Rejected status code: 503 Service Unavailable
[503] https://nbg1.your-objectstorage.com/osism/metalbox/registry-stable-full.tar.bz2 (at 134:4) | Rejected status code: 503 Service Unavailable
[503] https://nbg1.your-objectstorage.com/osism/metalbox/registry-stable-full.tar.bz2 (at 417:4) | Rejected status code: 503 Service Unavailable
[503] https://nbg1.your-objectstorage.com/osism/metalbox/ubuntu-noble.tar.bz2 (at 129:4) | Rejected status code: 503 Service Unavailable
[503] https://nbg1.your-objectstorage.com/osism/metalbox/ubuntu-noble.tar.bz2 (at 407:4) | Rejected status code: 503 Service Unavailable
[503] https://nbg1.your-objectstorage.com/osism/openstack-ironic-images/osism-esp.raw (at 115:6) | Rejected status code: 503 Service Unavailable
[503] https://nbg1.your-objectstorage.com/osism/openstack-ironic-images/osism-ipa.initramfs (at 111:6) | Rejected status code: 503 Service Unavailable
[503] https://nbg1.your-objectstorage.com/osism/openstack-ironic-images/osism-ipa.kernel (at 112:6) | Rejected status code: 503 Service Unavailable
[503] https://nbg1.your-objectstorage.com/osism/openstack-ironic-images/osism-metalbox-image.zip (at 96:4) | Rejected status code: 503 Service Unavailable
[503] https://nbg1.your-objectstorage.com/osism/openstack-ironic-images/osism-node.qcow2 (at 113:6) | Rejected status code: 503 Service Unavailable
[503] https://nbg1.your-objectstorage.com/osism/openstack-ironic-images/osism-node.qcow2.CHECKSUM (at 114:6) | Rejected status code: 503 Service Unavailable

Errors in docs/guides/deploy-guide/services/openstack.md
[TIMEOUT] https://www.openstack.org/software/project-navigator/openstack-components#openstack-services (at 14:5) | Request timed out

Errors in docs/guides/upgrade-guide/metalbox/data-updates.md
[503] https://nbg1.your-objectstorage.com/osism/metalbox/registry-stable-full.tar.bz2 (at 90:4) | Error (cached)
[503] https://nbg1.your-objectstorage.com/osism/metalbox/ubuntu-noble.tar.bz2 (at 151:4) | Error (cached)
[503] https://nbg1.your-objectstorage.com/osism/openstack-ironic-images/osism-esp.raw (at 57:6) | Error (cached)
[503] https://nbg1.your-objectstorage.com/osism/openstack-ironic-images/osism-ipa.initramfs (at 53:6) | Error (cached)
[503] https://nbg1.your-objectstorage.com/osism/openstack-ironic-images/osism-ipa.kernel (at 54:6) | Error (cached)
[503] https://nbg1.your-objectstorage.com/osism/openstack-ironic-images/osism-node.qcow2 (at 55:6) | Error (cached)
[503] https://nbg1.your-objectstorage.com/osism/openstack-ironic-images/osism-node.qcow2.CHECKSUM (at 56:6) | Error (cached)

Errors in docs/release-notes/osism-7.md
[TIMEOUT] https://www.openstack.org/software/openstack-bobcat (at 978:38) | Request timed out

Errors in docs/release-notes/osism-8.md
[TIMEOUT] https://www.openstack.org/software/openstack-caracal (at 223:38) | Request timed out

Hint: Followed 5 redirects. You might want to consider replacing redirecting URLs with the resolved URLs. Use verbose mode (`-v`/`-vv`) to see redirection details.

See detailed reports in MegaLinter artifacts

Your project could benefit from a custom flavor, which would allow you to run only the linters you need, and thus improve runtime performances. (Skip this info by defining FLAVOR_SUGGESTIONS: false)

  • Documentation: Custom Flavors
  • Command: npx mega-linter-runner@10.0.0 --custom-flavor-setup --custom-flavor-linters ACTION_ACTIONLINT,JSON_JSONLINT,JSON_V8R,JSON_PRETTIER,MARKDOWN_MARKDOWNLINT,MARKDOWN_MARKDOWN_TABLE_FORMATTER,REPOSITORY_CHECKOV,REPOSITORY_GIT_DIFF,REPOSITORY_BETTERLEAKS,REPOSITORY_SECRETLINT,REPOSITORY_TRUFFLEHOG,SPELL_LYCHEE,SPELL_CODESPELL,YAML_PRETTIER,YAML_YAMLLINT,YAML_V8R

MegaLinter is provided by OX Security
Show us your support by starring ⭐ the repository

Document the inconsistent scope enforcement for delegated tokens in
Keystone (Launchpad bugs #2153453 and #2158538, CVE ids pending).
Tokens derived from EC2 credentials and OAuth1 access tokens could
create trusts, application credentials and OAuth1 access tokens that
outlive the original credential and carry roles the delegation never
had, and application credential and EC2 tokens could be rescoped to
other projects through the token authentication method.

Every deployment is affected. No fixed Keystone release exists
upstream yet; OSISM ships the proposed upstream patches for 2025.1,
2025.2 and 2026.1 via container-images-kolla PR #776, which also
carries the ec2credential token ban from master. Community-curated
backports for 2024.1 and 2024.2 are in preparation. Overriding
keystone_tag is sufficient.

Assisted-by: Claude:claude-fable-5
Signed-off-by: Christian Berendt <berendt@osism.tech>
@berendt
berendt merged commit b0bb02d into main Aug 25, 2026
3 checks passed
@berendt
berendt deleted the ossa-2026-037 branch August 25, 2026 19:59
@github-project-automation github-project-automation Bot moved this from New to Done in Human Board Aug 25, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Archived in project

Development

Successfully merging this pull request may close these issues.

3 participants