Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 506
Alerts This Week
Warning Icon 1 506

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 19 articles for you...
172

Ubuntu OpenStack Keystone Critical Roles Bypass Vulnern USN-8433-1

Several security issues were fixed in OpenStack Keystone.. ========================================================================== Ubuntu Security Notice USN-8433-1 June 16, 2026 keystone vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 25.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: Several security issues were fixed in OpenStack Keystone. Software Description: - keystone: OpenStack identity service Details: It was discovered that OpenStack Keystone allowed restricted application credentials to create EC2 credentials. An authenticated attacker with only a reader role could possibly use this issue to bypass the role restrictions imposed on the application credential. (CVE-2026-33551) It was discovered that the OpenStack Keystone LDAP identity backend did not correctly convert the user enabled attribute to a boolean value. An attacker could possibly use this issue to authenticate as a user disabled in LDAP. This issue only affected Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 25.10. (CVE-2026-40683) It was discovered that OpenStack Keystone's application credential authentication plugin did not verify that the user supplied in an authentication request matched the credential owner. An authenticated attacker could possibly impersonate another user and gain access to their tokens and credentials. (CVE-2026-42998) It was discovered that OpenStack Keystone's RBAC policy enforcer unconditionally merged the raw JSON request body into the policy enforcement dictionary, overwriting trusted target data. An authenticated attacker could possibly use this issue to inject arbitrary policy attributes to bypass RBAC checks. (CVE-2026-42999) It was discovered that OpenStack Keystone allowed an attacker with the member role to escalate privileges to admin by chaining application credential impersonation with Keystone trusts. An attacker could possibly use this issueto create a persistent trust delegating the victim's admin role to themselves. (CVE-2026-43000) It was discovered that OpenStack Keystone did not validate that the project_id for an EC2 credential matched the project of the authenticating application credential. An attacker with valid credentials for one project could possibly use this issue to create EC2 credentials targeting a different project. (CVE-2026-43001) It was discovered that OpenStack Keystone's federated token rescoping mechanism did not propagate the original token's expiry to the newly issued token. A remote attacker could possibly use this issue to maintain access indefinitely by repeatedly rescoping tokens before expiry. (CVE-2026-44394) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS keystone 2:29.0.0-0ubuntu1.2 keystone-common 2:29.0.0-0ubuntu1.2 keystone-doc 2:29.0.0-0ubuntu1.2 python3-keystone 2:29.0.0-0ubuntu1.2 Ubuntu 25.10 keystone 2:28.0.0-0ubuntu1.3 keystone-common 2:28.0.0-0ubuntu1.3 keystone-doc 2:28.0.0-0ubuntu1.3 python3-keystone 2:28.0.0-0ubuntu1.3 Ubuntu 24.04 LTS keystone 2:25.0.0-0ubuntu1.4 keystone-common 2:25.0.0-0ubuntu1.4 keystone-doc 2:25.0.0-0ubuntu1.4 python3-keystone 2:25.0.0-0ubuntu1.4 Ubuntu 22.04 LTS keystone 2:21.0.1-0ubuntu2.4 keystone-common 2:21.0.1-0ubuntu2.4 keystone-doc 2:21.0.1-0ubuntu2.4 python3-keystone 2:21.0.1-0ubuntu2.4 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8433-1 CVE-2026-33551, CVE-2026-40683, CVE-2026-42998, CVE-2026-42999, CVE-2026-43000, CVE-2026-43001, CVE-2026-44394 Package Information: https://launchpad.net/ubuntu/+source/keystone/2:29.0.0-0ubuntu1.2 https://launchpad.net/ubuntu/+source/keystone/2:28.0.0-0ubuntu1.3 https://launchpad.net/ubuntu/+source/keystone/2:25.0.0-0ubuntu1.4 https://launchpad.net/ubuntu/+source/keystone/2:21.0.1-0ubuntu2.4 . Several serious security issues were addressed in OpenStack Keystone affecting multiple Ubuntu versions. Immediate updates are necessary.. OpenStack Keystone security update, Ubuntu identity service vulnerabilities, authentication privilege escalation. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 16, 2026 Critical Ubuntu
98

RedHat: RHSA-2020-3096-01 Important: OpenStack Keystone Security Update

An update for openstack-keystone is now available for Red Hat OpenStack Platform 10 (Newton). Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: openstack-keystone security update Advisory ID: RHSA-2020:3096-01 Product: Red Hat OpenStack Platform Advisory URL: https://access.redhat.com/errata/RHSA-2020:3096 Issue date: 2020-07-22 CVE Names: CVE-2020-12689 CVE-2020-12691 ==================================================================== 1. Summary: An update for openstack-keystone is now available for Red Hat OpenStack Platform 10 (Newton). Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat OpenStack Platform 10.0 - noarch 3. Description: The OpenStack Identity service (keystone) authenticates and authorizes OpenStack users by keeping track of users and their permitted activities. The Identity service supports multiple forms of authentication, including user name and password credentials, token-based systems, and AWS-style logins. Security Fix(es): * EC2 and credential endpoints are not protected from a scoped context (CVE-2020-12689) * Credentials endpoint policy logic allows changing credential owner and target project ID (CVE-2020-12691) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in thisadvisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1830384 - CVE-2020-12691 openstack-keystone: Credentials endpoint policy logic allows changing credential owner and target project ID 1830396 - CVE-2020-12689 openstack-keystone: EC2 and credential endpoints are not protected from a scoped context 6. Package List: Red Hat OpenStack Platform 10.0: Source: openstack-keystone-10.0.3-8.el7ost.src.rpm noarch: openstack-keystone-10.0.3-8.el7ost.noarch.rpm python-keystone-10.0.3-8.el7ost.noarch.rpm python-keystone-tests-10.0.3-8.el7ost.noarch.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2020-12689 https://access.redhat.com/security/cve/CVE-2020-12691 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2020 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBXxgtXtzjgjWX9erEAQji/w//WUEnILWwwslJHISwmn/vt1hAcY6ZaR0k qd0T80qlF294uogS+H9RzNLacDqvp0Z45CpUjcwJqrvUjEZIfSrJG94+pQLGmlQn xjlAnXkrSfnA9ECJgXwRiYHIxYnnr+tKwrSP6iqeVGcePlkJFyqXVkKOgevbn7SB O1gfGhC5UODXYBbfkjb/YRPyWjoMN7cwvtCNYe/F0F88zfypYfkffTvzhiEeqUnQ ffP3H1C/BZPy8B4cxCkSKZAJ27gPWBu4HdgMvSXVDqC9Wcrjiqv9cIzjDWP6FWWu kh8ldtMYUmWjk29LucGr64s1vDm+THDFyROb0abY+I8OXSCAp3vsGsEAaEfJMfzK psTkpOJwNN+fcAXwCRBoQ+pk4Wuw8ddFqlI3wnH2pQDNnMkkP7dNapxu8kyuXXJF VuioKhUygckaKS4rzWLDSTTK57ouCUllEKSYVggRA13UB/3nC2L+vsN5dizIfYKR b6hHUsibV/QvNHp3bJMK0M2Lxf2EmNK0wuZ5tFrrmhDN5twZniRAwkAz1G0EK09k 8YoRkbM0NLQAZmnnHTg8+8pOx/PLc4AXOy9BjRwLyJlr4adIWSJP3nW6xIvG1yei FlljsUQD0gYjOvYSXW94Qmp9ruAy5H2L9nSmZKwa+fhNT0/GKYewEiJ9eNWTY8tt 8Tdkv0zkCt8=w8b+ -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . A significant announcement regardingopenstack-keystone resolves urgent security vulnerabilities within Red Hat OpenStack Platform 10.. Red Hat OpenStack, openstack-keystone, security update, identity service, important security advisory. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 22, 2020 Important Red Hat
98

Red Hat OpenStack 13: RHSA-2020-2732-01 Important: Keystone Threat Fix

An update for openstack-keystone is now available for Red Hat OpenStack Platform 13 (Queens). Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: openstack-keystone security update Advisory ID: RHSA-2020:2732-01 Product: Red Hat OpenStack Platform Advisory URL: https://access.redhat.com/errata/RHSA-2020:2732 Issue date: 2020-06-24 CVE Names: CVE-2020-12689 CVE-2020-12691 CVE-2020-12692 ==================================================================== 1. Summary: An update for openstack-keystone is now available for Red Hat OpenStack Platform 13 (Queens). Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat OpenStack Platform 13.0 - noarch Red Hat OpenStack Platform 13.0 for RHEL 7.6 EUS Server - noarch 3. Description: The OpenStack Identity service (keystone) authenticates and authorizes OpenStack users by keeping track of users and their permitted activities. The Identity service supports multiple forms of authentication, including user name and password credentials, token-based systems, and AWS-style logins. Security Fix(es): * EC2 and credential endpoints are not protected from a scoped context (CVE-2020-12689) * Credentials endpoint policy logic allows changing credential owner and target project ID (CVE-2020-12691) * failure to check signature TTL of the EC2 credential auth method (CVE-2020-12692) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other relatedinformation, refer to the CVE page listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1830384 - CVE-2020-12691 openstack-keystone: Credentials endpoint policy logic allows changing credential owner and target project ID 1830396 - CVE-2020-12689 openstack-keystone: EC2 and credential endpoints are not protected from a scoped context 1831566 - Rebase openstack-keystone to 0cbf809 1833164 - CVE-2020-12692 openstack-keystone: failure to check signature TTL of the EC2 credential auth method 6. Package List: Red Hat OpenStack Platform 13.0 for RHEL 7.6 EUS Server: Source: openstack-keystone-13.0.4-3.el7ost.src.rpm noarch: openstack-keystone-13.0.4-3.el7ost.noarch.rpm python-keystone-13.0.4-3.el7ost.noarch.rpm Red Hat OpenStack Platform 13.0: Source: openstack-keystone-13.0.4-3.el7ost.src.rpm noarch: openstack-keystone-13.0.4-3.el7ost.noarch.rpm python-keystone-13.0.4-3.el7ost.noarch.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2020-12689 https://access.redhat.com/security/cve/CVE-2020-12691 https://access.redhat.com/security/cve/CVE-2020-12692 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2020 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBXvNJOtzjgjWX9erEAQim9A//VIs4m8x+I0OEsFRt/cpfNUFkqxkSNmbg PJVaniOZ9CQdWHJ9KLnhBc8ftmgfli0ofPchfAW6NytgIqENq7HA5LAwlkWokpzf sWrHHtPf4+4DSBJpysjtmowMTY3xtDB81/zN2RIwfybklcgGbuIt91OwyE7WfpRA 8M3/luRntGiez+HXrVZ+HDhJ/dw76rJkLlN4+xts4cHekefRmrLLWYLUEP9m5Tw0 WnrFCeqoXZxFF9Ea1o55Dtpb0w3FG/+lLYP86ys7nXf9uwQElthTGlZwBrUQZcUw pCIrxcY8vumGA8XL++OTGNq5QTgxuZGEjNPmjKal2vB6lw6jIOM64tFNbtvL0smX yPeooRNvCs6e/wU5nV+NB2DBd8A+NhyAQL8APKOQ2r2GoIV/BaVYkLDfNg9kmeuJ 4IbLL6uoBeVMWQfQC33wq4Ri4vWAxzHwECMY5Io19i/YC6lHDvRs+/tKBV8ybawv agZVG6gNCGzJccsY3/xmyrf8jq3xVanLx9Pcd39NSJk2vJC6PpeJYu15saxqpIlv qIpjSypwgoWfGLht4Adcj7zy61VKCG0Zi//sakN/CAoI47iCiaaVI2IIvDm+zEXG 8K9ExTkmgpiTsDZ8mzJ0hgTk0Fsk3eLXlEeaTVwPEocQN7dWoH17/OaOHOAVG9V8 +ABChT2GyAs=B6VQ -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Significant announcement regarding openstack-neutron tackles vital vulnerabilities within Red Hat OpenStack Platform 13.. security update, openstack keystone, Red Hat platform, important update. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 24, 2020 Important Red Hat
87

Debian: DSA-4679-1 Moderate: Keystone EC2 Credential Escalation

A vulnerability was found in the EC2 credentials API of Keystone, the OpenStack identity service: Any user authenticated within a limited scope (trust/oauth/application credential) could create an EC2 credential with an escalated permission, such as obtaining "admin" while . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4679-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff May 06, 2020 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : keystone CVE ID : not yet available Debian Bug : 959900 A vulnerability was found in the EC2 credentials API of Keystone, the OpenStack identity service: Any user authenticated within a limited scope (trust/oauth/application credential) could create an EC2 credential with an escalated permission, such as obtaining "admin" while the user is on a limited "viewer" role. For the stable distribution (buster), this problem has been fixed in version 2:14.2.0-0+deb10u1. We recommend that you upgrade your keystone packages. For the detailed security status of keystone please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/keystone Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . A critical security patch is available for Keystone, resolving a vulnerability related to EC2 credential escalation. Please ensure your Debian packages are upgraded without delay.. Keystone Security Update, EC2 Credential Escalation, Debian Advisory. . LinuxSecurity.com Team

Calendar%202 May 06, 2020 Debian
172

Ubuntu: 4262-1 Moderate: OpenStack Keystone Credential Exposure

OpenStack Keystone could be made to expose sensitive information over the network.. =========================================================================Ubuntu Security Notice USN-4262-1 January 30, 2020 keystone vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 19.10 Summary: OpenStack Keystone could be made to expose sensitive information over the network. Software Description: - keystone: OpenStack identity service Details: Daniel Preussker discovered that OpenStack Keystone incorrectly handled the list credentials API. A user with a role on the project could use this issue to view any other user's credentials. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 19.10: keystone 2:16.0.0-0ubuntu1.1 python3-keystone 2:16.0.0-0ubuntu1.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4262-1 CVE-2019-19687 Package Information: https://launchpad.net/ubuntu/+source/keystone/2:16.0.0-0ubuntu1.1 . OpenStack Nova exploit compromises private information. Upgrade your Debian installation to protect access keys. Find out more!. OpenStack Keystone, data exposure, Ubuntu update, credential leak, security advisory. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jan 30, 2020 Important Ubuntu
98

Red Hat OpenStack 13.0: RHSA-2018-2533 Important Info Exposure Issue

An update for openstack-keystone is now available for Red Hat OpenStack Platform 13.0 (Queens). Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: openstack-keystone security update Advisory ID: RHSA-2018:2533-01 Product: Red Hat Enterprise Linux OpenStack Platform Advisory URL: https://access.redhat.com/errata/RHSA-2018:2533 Issue date: 2018-08-21 CVE Names: CVE-2018-14432 ==================================================================== 1. Summary: An update for openstack-keystone is now available for Red Hat OpenStack Platform 13.0 (Queens). Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat OpenStack Platform 13.0 - noarch 3. Description: The OpenStack Identity service (keystone) authenticates and authorizes OpenStack users by keeping track of users and their permitted activities. The Identity service supports multiple forms of authentication, including user name and password credentials, token-based systems, and AWS-style logins. The following packages have been upgraded to a later upstream version: openstack-keystone (13.0.1). (BZ#1607221) Security Fix(es): * openstack-keystone: Information Exposure through /v3/OS-FEDERATION/projects (CVE-2018-14432) For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described inthis advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1606868 - CVE-2018-14432 openstack-keystone: Information Exposure through /v3/OS-FEDERATION/projects 6. Package List: Red Hat OpenStack Platform 13.0: Source: openstack-keystone-13.0.1-1.el7ost.src.rpm noarch: openstack-keystone-13.0.1-1.el7ost.noarch.rpm python-keystone-13.0.1-1.el7ost.noarch.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2018-14432 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2018 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBW3xCgdzjgjWX9erEAQisnA/9HTiOdYFzivoOqeSXjsmqnSQsdEaXnkgz idjtnxF3aJlzzEHV5EBHWP1hA96E2uqSOacNly+bfxQxbG8CM9C2/bfzHrGFhq/N LHduOkvzYtEsY0tmr6cJgvdlhlH9ehvlZeAZxPbdOl1qVkyMvYJMhdNJzi8AQEt2 p9qX3zJ64d8Y3kBzy6xEijyId1l7fVpvnaQHv+wWEJoN/Sfa9lqVSuWgND18GSLy Z0Fy5cgKV7r9erLX4usCuQz8GzLPlQFhh4Y5HYoN52V8kQo56pui0DebZ6aL0Yet yr76wERTVIWqEYznbQpFbGMe8F/VMTgqtOs2c4e+hmxwzwqNws+z6MvDsIvUeGv5 dwvpql5neiWHDwYc4VWbCuoXHxaHLCEAesrKSIoy9oe+9nomurbg9arro4uJi32p DVuftB+3YRJQFobCvpzfs/Ch6wM5oJMYOvAaQKB/TH0ztlijU1Hmob5d5lDQ55cf FnBhSvaCnCmka0Jastvc0/wZlwA6b04WsdlwREc9nzt/1rA4TxlUDIlIs1wqh1W+ Xt/Li4Iztz41g0CMFar6BjtUGXw9NbBqSUcTIcT+p2v3ukWdXV0Bnt7Mkhbu9M+r QaTEDD7O8ygKlo9f/3YuFHyqtGWR5USpWCe350wuHrYV7ASS7WBfLnt8S6R48iC4 yRcNBqJyKmY=Wqw9 -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Tackle significant OpenStack Keystone vulnerability within Red Hat OpenStack Platform by implementing this crucial patch.. Red Hat OpenStack, openstack-keystone, security update. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Aug 21, 2018 Important Red Hat
89

Fedora 23: 2015-13919 Critical: Ipsilon Authentication Service Update

ipsilon-1.0.0-5.fc23 - Backported some patches - Fix for CVE-2015-5215/CVE-2015-5216/CVE-2015-5217 ipsilon-1.0.0-5.fc22 - Backported some patches - Fix for CVE-2015-5215/CVE-2015-5216/CVE-2015-5217. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-13919 2015-11-01 01:51:21.184775 -------------------------------------------------------------------------------- Name : ipsilon Product : Fedora 23 Version : 1.0.0 Release : 5.fc23 URL : https://pagure.io/ipsilon Summary : An Identity Provider Server Description : Ipsilon is a multi-protocol Identity Provider service. Its function is to bridge authentication providers and applications to achieve Single Sign On and Federation. -------------------------------------------------------------------------------- Update Information: ipsilon-1.0.0-5.fc23 - Backported some patches - Fix for CVE-2015-5215/CVE-2015-5216/CVE-2015-5217 ipsilon-1.0.0-5.fc22 - Backported some patches - Fix for CVE-2015-5215/CVE-2015-5216/CVE-2015-5217 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update ipsilon' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/admin/lists/package-announce.lists.fedoraproject.org/ . Enhancement for Fedora 23 addressing identity service concerns and implementing security updates for significant vulnerabilities.. Ipsilon Update, Fedora Security, Identity Provider, Authentication Service, Backported Patches. . Severity: Critical.LinuxSecurity.com Team

Calendar%202 Nov 01, 2015 Critical Fedora
98

Red Hat: RHSA-2014:1789-01 Important: OpenStack Identity Service Flaw

Updated openstack-keystone packages that fix one security issue and several bugs are now available for Red Hat Enterprise Linux OpenStack Platform 5.0 for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having Important security. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ==================================================================== Red Hat Security Advisory Synopsis: Important: openstack-keystone security and bug fix update Advisory ID: RHSA-2014:1789-01 Product: Red Hat Enterprise Linux OpenStack Platform Advisory URL: https://access.redhat.com/errata/RHSA-2014:1789.html Issue date: 2014-11-03 CVE Names: CVE-2014-3621 ==================================================================== 1. Summary: Updated openstack-keystone packages that fix one security issue and several bugs are now available for Red Hat Enterprise Linux OpenStack Platform 5.0 for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having Important security impact. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available from the CVE link in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux OpenStack Platform 5.0 for RHEL 6 - noarch 3. Description: The OpenStack Identity service (keystone) authenticates and authorizes OpenStack users by keeping track of users and their permitted activities. The Identity service supports multiple forms of authentication, including user name and password credentials, token-based systems, and AWS-style logins. A flaw was found in the keystone catalog URL replacement. A user with permissions to register an endpoint could use this flaw to leak configuration data, including the master admin_token. Only keystone setups that allow non-cloud-admin users to create endpoints were affected by this issue. (CVE-2014-3621) Red Hat would like to thank the OpenStack project for reporting thisissue. Upstream acknowledges Brant Knudson from IBM as the original reporter. The openstack-keystone packages have been upgraded to upstream version 2014.1.3, which provides a number of bug fixes over the previous version. (BZ#1149748) All openstack-keystone users are advised to upgrade to these updated packages, which correct these issues. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1139937 - CVE-2014-3621 openstack-keystone: configuration data information leak through Keystone catalog 1149748 - Rebase openstack-keystone to 2014.1.3 6. Package List: Red Hat Enterprise Linux OpenStack Platform 5.0 for RHEL 6: Source: openstack-keystone-2014.1.3-2.el6ost.src.rpm noarch: openstack-keystone-2014.1.3-2.el6ost.noarch.rpm openstack-keystone-doc-2014.1.3-2.el6ost.noarch.rpm python-keystone-2014.1.3-2.el6ost.noarch.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2014-3621 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2014 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iD8DBQFUV0g3XlSAg2UNWIIRAobdAKCZWXmBAv/9ECKL9QsHCJzDCcpomACfYr0q 8IGpvSugwvMvU9oxcJNOARs=ZWPW -----END PGP SIGNATURE----- -- Enterprise-watch-list mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Important announcement regarding OpenStack Identity service resolves security flaws affecting Red Hat platforms.. OpenStack, Security Update, Red Hat, Identity Service, Configuration Leak. . Severity:Important. LinuxSecurity.com Team

Calendar%202 Nov 03, 2014 Important Red Hat
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200