|
|
Message-ID: <aRs9FhVD4FaD7TcF@yuggoth.org>
Date: Mon, 17 Nov 2025 15:19:50 +0000
From: Jeremy Stanley <fungi@...goth.org>
To: oss-security@...ts.openwall.com
Subject: Re: [OSSA-2025-002] OpenStack Keystone:
Unauthenticated access to EC2/S3 token endpoints can grant Keystone
authorization (CVE PENDING)
On 2025-11-16 21:05:22 +0100 (+0100), Salvatore Bonaccorso wrote:
>> =========================================================================
>> OSSA-2025-002: Unauthenticated access to EC2/S3 token endpoints can grant
>> Keystone authorization
>> =========================================================================
>[...]
>> Notes
>> ~~~~~
>[...]
>> - MITRE CVE Request 1930434 has been awaiting assignment since
>> 2025-09-24, but once completed will result in an errata revision to
>> this advisory reflecting the correct CVE ID. If any other CNA has
>> assigned a CVE themselves in the meantime, please reject it so that we
>> don't end up with duplicates.
>
>Have you ever heard back since then for a CVE assignment? I guess it
>felt through the cracks?
The coordinator who initially filed request 1930434 in September
followed up on the advisory publication date to let MITRE know it
was now public and request they prioritize assigning a CVE, but as
of the end of last week had still not heard back (I'll check in with
him again today once it's daylight in his locale, but don't have
high hopes the situation has changed).
We consider CVEs optional and don't hold up advisory publication for
them, but will officially issue errata and post to this mailing list
as soon as MITRE finally gets back to us. Thanks for checking in!
--
Jeremy Stanley
on behalf of the OpenStack Vulnerability Management Team
Download attachment "signature.asc" of type "application/pgp-signature" (964 bytes)
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.