Launch Week Day 1: Announcing Security Design Review
HIGH 7.5 PyPI

OpenStack Keystone allows /v3/ec2tokens or /v3/s3tokens request with valid AWS Signature to provide Keystone authorization.

GHSA-hcqg-5g63-7j9h · CVE-2025-65073

Published · Modified

Description

OpenStack Keystone before 26.0.1, 27.0.0, and 28.0.0 allows a /v3/ec2tokens or /v3/s3tokens request with a valid AWS Signature to provide Keystone authorization.

Ready to move

Start Securing

Free, no credit card | First findings in minutes