Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 515
Alerts This Week
Warning Icon 1 515

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 15 articles for you...
197

Debian 10 Buster: DLA-3714-1 critical: keystone data breach

Brief introduction CVE-2021-3563 . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3714-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Bastien Roucariès January 21, 2024 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : keystone Version : 2:14.2.0-0+deb10u2 CVE ID : CVE-2021-3563 CVE-2021-38155 Debian Bug : 992070 989998 Brief introduction CVE-2021-3563 A flaw was found in openstack-keystone. Only the first 72 characters of an application secret are verified allowing attackers bypass some password complexity which administrators may be counting on. The highest threat from this vulnerability is to data confidentiality and integrity. CVE-2021-38155 Keystone allowed information disclosure during account locking (related to PCI DSS features). By guessing the name of an account and failing to authenticate multiple times, any unauthenticated actor could both confirm the account exists and obtain that account's corresponding UUID, which might be leveraged for other unrelated attacks. All deployments enabling security_compliance.lockout_failure_attempts are affected. For Debian 10 buster, these problems have been fixed in version 2:14.2.0-0+deb10u2. We recommend that you upgrade your keystone packages. For the detailed security status of keystone please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/keystone Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . The latest advisory DLA-3714-1 for Debian LTS emphasizes significant security flaws within the keystone component.. Debian LTS Advisory, Keystone Security, Critical Flaws, Cybersecurity Risks. . Severity:Critical. LinuxSecurity.com Team

Calendar%202 Jan 21, 2024 Critical Debian LTS
172

Ubuntu 18.04 LTS USN-4480-1 Critical: Keystone Auth Issues

Several security issues were fixed in OpenStack Keystone.. =========================================================================Ubuntu Security Notice USN-4480-1 September 01, 2020 keystone vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 18.04 LTS Summary: Several security issues were fixed in OpenStack Keystone. Software Description: - keystone: OpenStack identity service Details: It was discovered that OpenStack Keystone incorrectly handled EC2 credentials. An authenticated attacker with a limited scope could possibly create EC2 credentials with escalated permissions. (CVE-2020-12689, CVE-2020-12691) It was discovered that OpenStack Keystone incorrectly handled the list of roles provided with OAuth1 access tokens. An authenticated user could possibly end up with more role assignments than intended. (CVE-2020-12690) It was discovered that OpenStack Keystone incorrectly handled EC2 signature TTL checks. A remote attacker could possibly use this issue to reuse Authorization headers. (CVE-2020-12692) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS: keystone 2:13.0.4-0ubuntu1 python-keystone 2:13.0.4-0ubuntu1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4480-1 CVE-2020-12689, CVE-2020-12690, CVE-2020-12691, CVE-2020-12692 Package Information: https://launchpad.net/ubuntu/+source/keystone/2:13.0.4-0ubuntu1 . Ubuntu 18.04 LTS Glance security patch resolves multiple elevation of privilege vulnerabilities.. Ubuntu Security, Keystone Issues, OpenStack Updates, Authentication Bugs. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Sep 01, 2020 Critical Ubuntu
87

Debian: DSA-4679-1 Moderate: Keystone EC2 Credential Escalation

A vulnerability was found in the EC2 credentials API of Keystone, the OpenStack identity service: Any user authenticated within a limited scope (trust/oauth/application credential) could create an EC2 credential with an escalated permission, such as obtaining "admin" while . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4679-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff May 06, 2020 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : keystone CVE ID : not yet available Debian Bug : 959900 A vulnerability was found in the EC2 credentials API of Keystone, the OpenStack identity service: Any user authenticated within a limited scope (trust/oauth/application credential) could create an EC2 credential with an escalated permission, such as obtaining "admin" while the user is on a limited "viewer" role. For the stable distribution (buster), this problem has been fixed in version 2:14.2.0-0+deb10u1. We recommend that you upgrade your keystone packages. For the detailed security status of keystone please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/keystone Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . A critical security patch is available for Keystone, resolving a vulnerability related to EC2 credential escalation. Please ensure your Debian packages are upgraded without delay.. Keystone Security Update, EC2 Credential Escalation, Debian Advisory. . LinuxSecurity.com Team

Calendar%202 May 06, 2020 Debian
98

Red Hat OpenStack 15: Important Keystone Credentials Issue RHSA-2019-4358-01

An update for openstack-keystone is now available for Red Hat OpenStack Platform 15 (Stein). Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: openstack-keystone security update Advisory ID: RHSA-2019:4358-01 Product: Red Hat Enterprise Linux OpenStack Platform Advisory URL: https://access.redhat.com/errata/RHSA-2019:4358 Issue date: 2019-12-19 CVE Names: CVE-2019-19687 ==================================================================== 1. Summary: An update for openstack-keystone is now available for Red Hat OpenStack Platform 15 (Stein). Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat OpenStack Platform 15.0 - noarch 3. Description: The OpenStack Identity service (keystone) authenticates and authorizes OpenStack users by keeping track of users and their permitted activities. The Identity service supports multiple forms of authentication, including user name and password credentials, token-based systems, and AWS-style logins. Security Fix(es): * Credentials API allows non-admin to list and retrieve all userscredentials (CVE-2019-19687) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed(https://bugzilla.redhat.com/): 1781470 - CVE-2019-19687 openstack-keystone: Credentials API allows non-admin to list and retrieve all users credentials 6. Package List: Red Hat OpenStack Platform 15.0: Source: openstack-keystone-15.0.1-0.20190720060412.5f27c4b.1.el8ost.src.rpm noarch: openstack-keystone-15.0.1-0.20190720060412.5f27c4b.1.el8ost.noarch.rpm python3-keystone-15.0.1-0.20190720060412.5f27c4b.1.el8ost.noarch.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2019-19687 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2019 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBXfvPCtzjgjWX9erEAQhscA/+JPQtUDhyQwtzei16r9+RMXMNu9kzScZc ZaRJXZuF3nyG3qoOI2GPoS8Vn3oVvW2sHgpJczoWusW2tBtuupPK02ezuRFCNx31 i8PqIu9WYJL11UeCSrlyemIC6c0VR4K5+b/i+crmDvBoTzJLDL7TUb8EqznjhGhA lvFAvEGbAE2yM8YXMS/mMh/1VK8Mxo7jIYXLODr1rV6x1F+9SquYcnKC8ehMNfui ZuOlConk+cZtJuU29VR0d6JVNox9VQujT0nLyUyAJBE3ZMm5YgwBps9WGunTpTcJ UDWal2TMGEXxtE+LZrK4aeNoZvsKGVHxVYcry9zcKW94/k84krSW8PixUxZBNTXc xm+Dbk1twjsnnJq2nNL/FdujExs1O8YO30t5Ruy1oIYqKOShMkBhfhcnjLccytTf L4x3+n8vtFHTEreT5/Ie3QW5AVxUwsaWSxoMkg+9NyMEdbnVW5VIpuFJ6NlmilBC 4R4aMz5u0RRTxkElAgJVirQ9NogKNmUK1G/7O9LkBEMDUScWuqvTPIS18zrM7Kb+ Z/zGmD2ObTqP6x5zKSbvxYigqCdr0UzEz34zvlCi2qsbQereMwvTunNEebJTsayX RRt3Bjdyy1SBgLn1XvNDOS86MyNjM/Wu33Abv+f476luNT+1cnmj6ZfhprqiUYvQ XrjAwnHgF+w=XY9T -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . OpenStack Keystone security patch for Red Hat addresses crucial credentials exposure problem. Installation of updated packages advised.. Red Hat OpenStack, openstack-keystone, security update, access control, credentials API. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Dec 19, 2019 Important Red Hat
87

Debian Stretch: DSA-4275-1 Moderate: Keystone Info Leak

Kristi Nikolla discovered an information leak in Keystone, the OpenStack identity service, if running in a federated setup. For the stable distribution (stretch), this problem has been fixed in . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4275-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff August 16, 2018 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : keystone CVE ID : CVE-2018-14432 Debian Bug : 904616 Kristi Nikolla discovered an information leak in Keystone, the OpenStack identity service, if running in a federated setup. For the stable distribution (stretch), this problem has been fixed in version 2:10.0.0-9+deb9u1. We recommend that you upgrade your keystone packages. For the detailed security status of keystone please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/keystone Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Hash: SHA512 Debian Security Advisory DSA-4275-1 https://www.debian.org/security/ Moritz Muehlenhoff. kristi, nikolla, information, keystone, openstack, identity, service, runnin. . LinuxSecurity.com Team

Calendar%202 Aug 16, 2018 Debian
172

Ubuntu 15.04/14.04 LTS USN-2705-1 Moderate: Keystone MITM Vulnerability

Keystone could be made to expose sensitive information over thenetwork.. =========================================================================Ubuntu Security Notice USN-2705-1 August 06, 2015 python-keystoneclient, python-keystonemiddleware vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 15.04 - Ubuntu 14.04 LTS Summary: Keystone could be made to expose sensitive information over the network. Software Description: - python-keystoneclient: Client library for OpenStack Identity API - python-keystonemiddleware: Client library for OpenStack Identity API Details: Qin Zhao discovered Keystone disabled certification verification when the "insecure" option is set in a paste configuration (paste.ini) file regardless of the value, which allows remote attackers to conduct man-in-the-middle attacks via a crafted certificate. (CVE-2014-7144) Brant Knudson discovered Keystone disabled certification verification when the "insecure" option is set in a paste configuration (paste.ini) file regardless of the value, which allows remote attackers to conduct man-in-the-middle attacks via a crafted certificate. (CVE-2015-1852) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 15.04: python-keystoneclient 1:1.2.0-0ubuntu1.1 python-keystonemiddleware 1.5.0-0ubuntu1.1 Ubuntu 14.04 LTS: python-keystoneclient 1:0.7.1-ubuntu1.2 After a standard system update you need to restart Keystone to make all the necessary changes. References: CVE-2014-7144, CVE-2015-1852 Package Information: https://launchpad.net/ubuntu/+source/python-keystoneclient/1:1.2.0-0ubuntu1.1 https://launchpad.net/ubuntu/+source/python-keystonemiddleware/1.5.0-0ubuntu1.1 https://launchpad.net/ubuntu/+source/python-keystoneclient/1:0.7.1-ubuntu1.2 . Secure your Keystone deployment on Ubuntu by updating packages, reviewingconfigs, enforcing secure networking, and regularly monitoring logs for better protection. Keystone Security Issues, Ubuntu Updates, Man-in-the-Middle Attack, Python Keystone Client, Client Library Security. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Aug 06, 2015 Important Ubuntu
98

Red Hat EL OpenStack 5.0 RHSA-2014:1789-01 Important Keystone Issue

Updated openstack-keystone packages that fix one security issue and several bugs are now available for Red Hat Enterprise Linux OpenStack Platform 5.0 for Red Hat Enterprise Linux 6. [More...]. ==================================================================== Red Hat Security Advisory Synopsis: Important: openstack-keystone security and bug fix update Advisory ID: RHSA-2014:1789-01 Product: Red Hat Enterprise Linux OpenStack Platform Advisory URL: https://access.redhat.com/errata/RHSA-2014:1789.html Issue date: 2014-11-03 CVE Names: CVE-2014-3621 ==================================================================== 1. Summary: Updated openstack-keystone packages that fix one security issue and several bugs are now available for Red Hat Enterprise Linux OpenStack Platform 5.0 for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having Important security impact. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available from the CVE link in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux OpenStack Platform 5.0 for RHEL 6 - noarch 3. Description: The OpenStack Identity service (keystone) authenticates and authorizes OpenStack users by keeping track of users and their permitted activities. The Identity service supports multiple forms of authentication, including user name and password credentials, token-based systems, and AWS-style logins. A flaw was found in the keystone catalog URL replacement. A user with permissions to register an endpoint could use this flaw to leak configuration data, including the master admin_token. Only keystone setups that allow non-cloud-admin users to create endpoints were affected by this issue. (CVE-2014-3621) Red Hat would like to thank the OpenStack project for reporting this issue. Upstream acknowledges Brant Knudson from IBM as the original reporter. The openstack-keystone packages havebeen upgraded to upstream version 2014.1.3, which provides a number of bug fixes over the previous version. (BZ#1149748) All openstack-keystone users are advised to upgrade to these updated packages, which correct these issues. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1139937 - CVE-2014-3621 openstack-keystone: configuration data information leak through Keystone catalog 1149748 - Rebase openstack-keystone to 2014.1.3 6. Package List: Red Hat Enterprise Linux OpenStack Platform 5.0 for RHEL 6: Source: openstack-keystone-2014.1.3-2.el6ost.src.rpm noarch: openstack-keystone-2014.1.3-2.el6ost.noarch.rpm openstack-keystone-doc-2014.1.3-2.el6ost.noarch.rpm python-keystone-2014.1.3-2.el6ost.noarch.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2014-3621 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2014 Red Hat, Inc. . Revised openstack-keystone software resolves a security vulnerability and various bugs in Red Hat Enterprise Linux OpenStack Platform version 5.0.. OpenStack Security Fix, Red Hat Update, Keystone Configuration Leak. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Nov 03, 2014 Important Red Hat
98

Red Hat 7: RHSA-2014:1790-01 Important Security Fix for OpenStack Keystone

Updated openstack-keystone packages that fix one security issue and several bugs are now available for Red Hat Enterprise Linux OpenStack Platform 5.0 for Red Hat Enterprise Linux 7. [More...]. ==================================================================== Red Hat Security Advisory Synopsis: Important: openstack-keystone security and bug fix update Advisory ID: RHSA-2014:1790-01 Product: Red Hat Enterprise Linux OpenStack Platform Advisory URL: https://access.redhat.com/errata/RHSA-2014:1790.html Issue date: 2014-11-03 CVE Names: CVE-2014-3621 ==================================================================== 1. Summary: Updated openstack-keystone packages that fix one security issue and several bugs are now available for Red Hat Enterprise Linux OpenStack Platform 5.0 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having Important security impact. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available from the CVE link in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux OpenStack Platform 5.0 for RHEL 7 - noarch 3. Description: The OpenStack Identity service (keystone) authenticates and authorizes OpenStack users by keeping track of users and their permitted activities. The Identity service supports multiple forms of authentication, including user name and password credentials, token-based systems, and AWS-style logins. A flaw was found in the keystone catalog URL replacement. A user with permissions to register an endpoint could use this flaw to leak configuration data, including the master admin_token. Only keystone setups that allow non-cloud-admin users to create endpoints were affected by this issue. (CVE-2014-3621) Red Hat would like to thank the OpenStack project for reporting this issue. Upstream acknowledges Brant Knudson from IBM as the original reporter. The openstack-keystone packages havebeen upgraded to upstream version 2014.1.3, which provides a number of bug fixes over the previous version. (BZ#1149736) All openstack-keystone users are advised to upgrade to these updated packages, which correct these issues. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1113534 - LDAP misconfiguration should be handled better 1116551 - Can't get a token with curl when keystone is running in Apache with LDAP 1139937 - CVE-2014-3621 openstack-keystone: configuration data information leak through Keystone catalog 1140152 - Keystone LDAPS connection using CA certificate 1149425 - Include policy.v3cloudsample.json example 1149736 - Rebase openstack-keystone to 2014.1.3 6. Package List: Red Hat Enterprise Linux OpenStack Platform 5.0 for RHEL 7: Source: openstack-keystone-2014.1.3-2.el7ost.src.rpm noarch: openstack-keystone-2014.1.3-2.el7ost.noarch.rpm openstack-keystone-doc-2014.1.3-2.el7ost.noarch.rpm python-keystone-2014.1.3-2.el7ost.noarch.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2014-3621 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2014 Red Hat, Inc. . Recent updates to openstack-keystone packages address a security vulnerability and various bugs for the Red Hat Enterprise Linux OpenStack Platform.. OpenStack Security Fix, Red Hat Update, Keystone Bug Fix, Linux OpenStack. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Nov 03, 2014 Important Red Hat
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200