Your submission was sent successfully! Close

CVE-2021-3563

Published: 26 August 2022

A flaw was found in openstack-keystone. Only the first 72 characters of an application secret are verified allowing attackers bypass some password complexity which administrators may be counting on. The highest threat from this vulnerability is to data confidentiality and integrity.

Notes

AuthorNote
mdeslaur
no indication of possible fix from upstream as of 2022-09-12
Priority

Low

CVSS 3 base score: 9.1

Status

Package Release Status
keystone
Launchpad, Ubuntu, Debian
bionic Deferred
(2022-09-12)
focal Deferred
(2022-09-12)
groovy Ignored
(reached end-of-life)
hirsute Ignored
(reached end-of-life)
impish Ignored
(reached end-of-life)
jammy Deferred
(2022-09-12)
trusty Does not exist

upstream Needs triage

xenial Deferred
(2022-09-12)