vulnerability

Ubuntu: USN-7926-1 (CVE-2025-65073): OpenStack Keystone vulnerabilities

Severity
8
CVSS
(AV:N/AC:M/Au:N/C:P/I:C/A:N)
Published
Nov 4, 2025
Added
Nov 19, 2025
Modified
Dec 15, 2025

Description

Kay discovered that OpenStack Keystone incorrectly handled the ec2tokens
and s3tokens APIs. A remote attacker could possibly use this issue to
obtain unauthorized access and escalate privileges. (CVE-2025-65073)

It was discovered that OpenStack Keystone only validated the first 72
bytes of an application secret. An attacker could possibly use this issue
to bypass password complexity. (CVE-2021-3563)

It was discovered that OpenStack Keystone had a time lag before a token
should be revoked by the security policy. A remote administrator could use
this issue to maintain access for longer than expected. (CVE-2022-2447)

Solutions

ubuntu-upgrade-keystoneubuntu-upgrade-python3-keystone
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.