An issue was discovered in OpenStack keystonemiddleware 10.5 through 10.7 before 10.7.2, 10.8 and 10.9 before 10.9.1, and 10.10 through 10.12 before 10.12.1. The external_oauth2_token middleware fail…
严重 CVSS 9.9
摘要
An issue was discovered in OpenStack keystonemiddleware 10.5 through 10.7 before 10.7.2, 10.8 and 10.9 before 10.9.1, and 10.10 through 10.12 before 10.12.1. The external_oauth2_token middleware fails to sanitize incoming authentication headers before processing OAuth 2.0 tokens. By sending forged identity headers such as X-Is-Admin-Project, X-Roles, or X-User-Id, an authenticated attacker may escalate privileges or impersonate other users. All deployments using the external_oauth2_token middle…
中文摘要建设中,暂以英文摘要呈现(DR-003 v2)。
深度研判 · 自动通道
该漏洞尚未生成深度研判报告(DR-003 v2 AI pipeline 建设中)。
数据来源
- NVD DATABASE
原始链接
- https://launchpad.net/bugs/2129018
- https://www.openwall.com/lists/oss-security/2026/01/16/9
- http://www.openwall.com/lists/oss-security/2026/01/15/1
- http://www.openwall.com/lists/oss-security/2026/01/16/2
- http://www.openwall.com/lists/oss-security/2026/01/16/3
- http://www.openwall.com/lists/oss-security/2026/01/16/9
- https://access.redhat.com/errata/RHSA-2026:3402
- https://access.redhat.com/errata/RHSA-2026:3855
- https://access.redhat.com/errata/RHSA-2026:4434
- https://access.redhat.com/errata/RHSA-2026:5133
- https://access.redhat.com/errata/RHSA-2026:5907
- https://access.redhat.com/security/cve/CVE-2026-22797
- https://bugzilla.redhat.com/show_bug.cgi?id=2430879
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-22797.json
时间线
- nvd_ingest NVD