Login
Newsletter
Werbung

Sicherheit: Mangelnde Rechteprüfung in OpenStack
Aktuelle Meldungen Distributionen
Name: Mangelnde Rechteprüfung in OpenStack
ID: USN-7857-1
Distribution: Ubuntu
Plattformen: Ubuntu 24.04 LTS, Ubuntu 25.04, Ubuntu 25.10
Datum: Di, 4. November 2025, 22:54
Referenzen: Keine Angabe
Applikationen: OpenStack

Originalnachricht

--===============1954480269860835595==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit

==========================================================================
Ubuntu Security Notice USN-7857-1
November 04, 2025

keystone vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 25.10
- Ubuntu 25.04
- Ubuntu 24.04 LTS

Summary:

OpenStack Keystone could allow unintended access to network services.

Software Description:
- keystone: OpenStack identity service

Details:

Kay discovered that OpenStack Keystone incorrectly handled the ec2tokens
and s3tokens APIs. A remote attacker could possibly use this issue to
obtain unauthorized access and escalate privileges.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 25.10
keystone 2:28.0.0-0ubuntu1.1
python3-keystone 2:28.0.0-0ubuntu1.1

Ubuntu 25.04
keystone 2:27.0.0-0ubuntu1.1
python3-keystone 2:27.0.0-0ubuntu1.1

Ubuntu 24.04 LTS
keystone 2:25.0.0-0ubuntu1.1
python3-keystone 2:25.0.0-0ubuntu1.1

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-7857-1
https://launchpad.net/bugs/2130629

Package Information:
https://launchpad.net/ubuntu/+source/keystone/2:28.0.0-0ubuntu1.1
https://launchpad.net/ubuntu/+source/keystone/2:27.0.0-0ubuntu1.1
https://launchpad.net/ubuntu/+source/keystone/2:25.0.0-0ubuntu1.1

--===============1954480269860835595==
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature

-----BEGIN PGP SIGNATURE-----

iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmkKb4kACgkQcpJm3tlz
hgFxBg//VxyhCGfXLOdTkDDqBDvBPAAHkY2wwB1i9yndYHpHibkLtoNENRYf1qe6
UruZxbsGIoAWFmXGM1H3a/4ALXfKTVpdeTS5QKEaFL+y8BE8jmjKWzpWcIaekyf4
XnG6rfoUMgDsyLfSVXjzrBQKWZpLIrpTEZ0RIglicPVYkic6cHxfphRkMTKMle9/
rX6e1/77tcyZx61ZsrQNhHhliiEtAf+M8A/qelqwL0oFJcj6tTmml6Y3bFcCjVSy
x/MBwytNkxCy2i5WnJCo7mepcNSN3WSi0kAyouNXOrEX6tQmlpnO2bvTI/EeNY7w
WPMQCEsUiqLTrFX/5eMvV46j1SE5o+u1rIGlvIf/rFDrxEanI7q/5E3D60iqSV1C
XZBcwh4tYIkmfNl5UX5+OuV6b10gsgl9ahK9wPaocdvJ0YMuGwqsIm8O1MRGgE7e
1Bayzo3OdDwTMqA8g7QDA/JddKyGBFVE1w5tMlxY6nroL2OEjX5u151HILe3X7J4
nejMPM2tdxu2y8eaZy+TSPFapPhjMW+9Lr4e0MsuDj0EOdMmudlajSMzpoZO4ZrL
EpvUN2fyULDm+Yqw2rPB9nnzDhMktZOWNXm04dFmSMms13UWw4cGurEUBI+DffYk
4MHKfo3jZkvY1ReTjf5wr2d0skzTLDX84w17PdpjCcNfw12aHoU=
=G1BZ
-----END PGP SIGNATURE-----

--===============1954480269860835595==--
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung