Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <aRs9FhVD4FaD7TcF@yuggoth.org>
Date: Mon, 17 Nov 2025 15:19:50 +0000
From: Jeremy Stanley <fungi@...goth.org>
To: oss-security@...ts.openwall.com
Subject: Re: [OSSA-2025-002] OpenStack Keystone:
 Unauthenticated access to EC2/S3 token endpoints can grant Keystone
 authorization (CVE PENDING)

On 2025-11-16 21:05:22 +0100 (+0100), Salvatore Bonaccorso wrote:
>> =========================================================================
>> OSSA-2025-002: Unauthenticated access to EC2/S3 token endpoints can grant
>>                Keystone authorization
>> =========================================================================
>[...]
>> Notes
>> ~~~~~
>[...]
>> - MITRE CVE Request 1930434 has been awaiting assignment since
>>   2025-09-24, but once completed will result in an errata revision to
>>   this advisory reflecting the correct CVE ID. If any other CNA has
>>   assigned a CVE themselves in the meantime, please reject it so that we
>>   don't end up with duplicates.
>
>Have you ever heard back since then for a CVE assignment? I guess it 
>felt through the cracks?

The coordinator who initially filed request 1930434 in September 
followed up on the advisory publication date to let MITRE know it 
was now public and request they prioritize assigning a CVE, but as 
of the end of last week had still not heard back (I'll check in with 
him again today once it's daylight in his locale, but don't have 
high hopes the situation has changed).

We consider CVEs optional and don't hold up advisory publication for 
them, but will officially issue errata and post to this mailing list 
as soon as MITRE finally gets back to us. Thanks for checking in!
-- 
Jeremy Stanley
on behalf of the OpenStack Vulnerability Management Team

Download attachment "signature.asc" of type "application/pgp-signature" (964 bytes)

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.