CVE-2015-7546High· 7.5▾ TwilightOpenStack Identity Keystone and keystonemiddleware Insufficiently Protected Credentials
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.3 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 13.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
1.7%
1.7% → 1.7%
The identity service in OpenStack Identity (Keystone) before 2015.1.3 (Kilo) and 8.0.x before 8.0.2 (Liberty) and keystonemiddleware (formerly python-keystoneclient) before 1.5.4 (Kilo) and Liberty before 2.3.3 does not properly invalidate authorization tokens when using the PKI or PKIZ token providers, which allows remote authenticated users to bypass intended access restrictions and gain access to cloud resources by manipulating byte fields within a revoked token.
keystone >= 9.0.0.0b1, < 9.0.0.0b2keystonemiddleware >= 2.4.0, < 4.1.0keystone >= 8.0, < 8.1.0keystonemiddleware < 1.5.4keystonemiddleware >= 1.6.0, < 2.3.3Upgrade to a patched release:
keystone 9.0.0.0b2keystonemiddleware 4.1.0keystone 8.1.0keystonemiddleware 1.5.4keystonemiddleware 2.3.3Connected by shared product, vendor, weakness, or advisory.
CVE-2012-3542High· 7.5OpenStack Keystone Allows Remote User Account Creation
CVE-2017-2673High· 7.2An authorization-check flaw was discovered in federation configurations of the OpenStack Identity service (keystone). An authenticated fe…
CVE-2013-1865NoneOpenStack Keystone Folsom (2012.2) does not properly perform revocation checks for Keystone PKI tokens when done through a server, which …
CVE-2012-4457MediumOpenStack Keystone Token authorization for a user in a disabled tenant is allowed
CVE-2026-44394Medium· 6.0OpenStack Keystone's federated token rescoping mechanism doesn't propagate the original token's expiry to the newly issued token
CVE-2026-43000Medium· 6.0OpenStack Keystone has an Incorrect Authorization issue