---
title: "CVE-2021-3563\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2021-3563?format=md
keywords: index, follow
---

# CVE-2021-3563

Publication date 26 August 2022

Last updated 11 December 2025

---

Ubuntu priority

**Low**

[Why this priority?](https://ubuntu.com/security/CVE-2021-3563?format=md#priority-reason )

## Cvss 3 Severity Score

**7.4 · High**

[Score breakdown](https://ubuntu.com/security/CVE-2021-3563?format=md#impact-score)

Toggle side navigation

## Description

A flaw was found in openstack-keystone. Only the first 72 characters of an
application secret are verified allowing attackers bypass some password
complexity which administrators may be counting on. The highest threat from
this vulnerability is to data confidentiality and integrity.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2021-3563?format=md#notes)

### Why is this CVE low priority?

Upstream keystone developers have rated this to be a low severity issue

[Learn more about Ubuntu priority](https://ubuntu.com/security/cves/about#priority)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| keystone | 26.04 LTS resolute | Not affected |
| 25.10 questing | Not affected |
| 25.04 plucky | Not affected |
| 24.10 oracular | Ignored end of life, was deferred [2023-01-03] |
| 24.04 LTS noble | Not affected |
| 23.10 mantic | Ignored end of life, was deferred [2023-01-03] |
| 23.04 lunar | Ignored end of life, was deferred [2023-01-03] |
| 22.10 kinetic | Ignored end of life, was deferred [2023-01-03] |
| 22.04 LTS jammy | Fixed 2:21.0.1-0ubuntu2.1 |
| 21.10 impish | Ignored end of life |
| 21.04 hirsute | Ignored end of life |
| 20.10 groovy | Ignored end of life |
| 20.04 LTS focal | Vulnerable |
| 18.04 LTS bionic | Vulnerable |
| 16.04 LTS xenial | Vulnerable |
| 14.04 LTS trusty | Not in release |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Notes

---

### [mdeslaur](https://launchpad.net/~mdeslaur)

fixed in 21.0.1, 22.0.1, 23.0.0.0rc1

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

7.4 · High

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Network |
  | Attack complexity | High |
  | Privileges required | None |
  | User interaction | None |
  | Scope | Unchanged |
  | Confidentiality impact | High |
  | Integrity impact | High |
  | Availability impact | None |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 7.4 · High |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3563)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2021-3563)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2021-3563)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2021-3563)

### Related Ubuntu Security Notices (USN)

+ [USN-7926-1](https://usn.ubuntu.com/USN-7926-1)
+ OpenStack Keystone vulnerabilities
+ 11 December 2025

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2021-3563>
