CVE-2021-3563

A flaw was found in openstack-keystone. Only the first 72 characters of an application secret are verified allowing attackers bypass some password complexity which administrators may be counting on. The highest threat from this vulnerability is to data confidentiality and integrity.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.4 HIGH
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 6%
VendorProductVersion
openstackkeystone
*
debiandebian_linux
10.0
debiandebian_linux
11.0
redhatopenstack_platform
10.0
redhatopenstack_platform
13.0
redhatopenstack_platform
16.1
redhatopenstack_platform
16.2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
keystone
bullseye
no-dsa
bookworm
no-dsa
sid
2:26.0.0-1
fixed
trixie
2:26.0.0-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
keystone
noble
deferred
mantic
ignored
lunar
ignored
kinetic
ignored
jammy
deferred
impish
ignored
hirsute
ignored
groovy
ignored
focal
deferred
bionic
deferred
xenial
deferred
trusty
dne