Alerts This Week
Warning Icon 1 923
Alerts This Week
Warning Icon 1 923

Debian 10 Buster: DLA-3714-1 critical: keystone data breach

debian lts
Calendar Grey January 21, 2024
Dist Debian Esm H88
The latest advisory DLA-3714-1 for Debian LTS emphasizes significant security flaws within the keystone component.
Brief introduction CVE-2021-3563

Summary

CVE-2021-3563

A flaw was found in openstack-keystone. Only the first 72 characters
of an application secret are verified allowing attackers bypass some
password complexity which administrators may be counting on.
The highest threat from this vulnerability is to data confidentiality
and integrity.

CVE-2021-38155

Keystone allowed information disclosure during account locking
(related to PCI DSS features). By guessing the name of an account
and failing to authenticate multiple times, any unauthenticated actor
could both confirm the account exists and obtain that account's
corresponding UUID, which might be leveraged for other unrelated
attacks. All deployments enabling
security_compliance.lockout_failure_attempts are affected.

For Debian 10 buster, these problems have been fixed in version
2:14.2.0-0+deb10u2.

We recommend that you upgrade your keystone packages.

For the detailed security status of keystone please refer to
its security tracker page at:

Read the Full Advisory


Severity
critical
Lowest
Low
Medium
High
Critical

Package: keystone
Version: 2:14.2.0-0+deb10u2
CVE ID: CVE-2021-3563 CVE-2021-38155
Debian Bug: 992070 989998

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here