CVE-2021-3563
published 2022-08-26CVE-2021-3563: A flaw was found in openstack-keystone. Only the first 72 characters of an application secret are verified allowing attackers bypass some password complexity…
PriorityP345high7.4CVSS 3.1
AVNACHPRNUINSUCHIHAN
EPSS
1.32%
67.5th percentile
A flaw was found in openstack-keystone. Only the first 72 characters of an application secret are verified allowing attackers bypass some password complexity which administrators may be counting on. The highest threat from this vulnerability is to data confidentiality and integrity.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | keystone | < keystone 2:23.0.0-3 (forky) | keystone 2:23.0.0-3 (forky) |
| openstack | keystone | >= 0 < 2:23.0.0-3 | 2:23.0.0-3 |
| openstack | keystone | >= 0 < 2:23.0.0-3 | 2:23.0.0-3 |
| openstack | keystone | >= 0 < 2:21.0.1-0ubuntu2.1 | 2:21.0.1-0ubuntu2.1 |
| openstack | keystone | 0 – 21.0.0 | — |
| redhat | openstack_platform | — | — |
| redhat | openstack_platform | — | — |
| redhat | openstack_platform | — | — |
| redhat | openstack_platform | — | — |
CVSS provenance
nvdv3.17.4HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
osv7.4HIGH
vendor_debian7.4HIGH
vendor_redhat7.4HIGH
vendor_ubuntu7.4HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
keystone vulnerabilities
osv·2025-12-11·CVSS 7.4
CVE-2025-65073 [HIGH] keystone vulnerabilities
keystone vulnerabilities
Kay discovered that OpenStack Keystone incorrectly handled the ec2tokens
and s3tokens APIs. A remote attacker could possibly use this issue to
obtain unauthorized access and escalate privileges. (CVE-2025-65073)
It was discovered that OpenStack Keystone only validated the first 72
bytes of an application secret. An attacker could possibly use this issue
to bypass password complexity. (CVE-2021-3563)
It was discovered that OpenStack Keystone had a time lag before a token
should be revoked by the security policy. A remote administrator could use
this issue to maintain access for longer than expected. (CVE-2022-2447)
GHSA
Openstack Keystone Incorrect Authorization vulnerability
ghsa·2022-08-27
CVE-2021-3563 [CRITICAL] CWE-863 Openstack Keystone Incorrect Authorization vulnerability
Openstack Keystone Incorrect Authorization vulnerability
A flaw was found in openstack-keystone, only the first 72 characters of an application secret are verified allowing attackers bypass some password complexity which administrators may be counting on. The highest threat from this vulnerability is to data confidentiality and integrity. A [patch](https://opendev.org/openstack/keystone/commit/7859ed26003858ebfd9a5e866b43f1a6a9e83dca) is available.
OSV
Openstack Keystone Incorrect Authorization vulnerability
osv·2022-08-27
CVE-2021-3563 [CRITICAL] Openstack Keystone Incorrect Authorization vulnerability
Openstack Keystone Incorrect Authorization vulnerability
A flaw was found in openstack-keystone, only the first 72 characters of an application secret are verified allowing attackers bypass some password complexity which administrators may be counting on. The highest threat from this vulnerability is to data confidentiality and integrity. A [patch](https://opendev.org/openstack/keystone/commit/7859ed26003858ebfd9a5e866b43f1a6a9e83dca) is available.
OSV
CVE-2021-3563: A flaw was found in openstack-keystone
osv·2022-08-26·CVSS 7.4
CVE-2021-3563 [HIGH] CVE-2021-3563: A flaw was found in openstack-keystone
A flaw was found in openstack-keystone. Only the first 72 characters of an application secret are verified allowing attackers bypass some password complexity which administrators may be counting on. The highest threat from this vulnerability is to data confidentiality and integrity.
Ubuntu
OpenStack Keystone vulnerabilities
vendor_ubuntu·2025-12-11·CVSS 7.4
CVE-2022-2447 [HIGH] OpenStack Keystone vulnerabilities
Title: OpenStack Keystone vulnerabilities
Summary: Several security issues were fixed in OpenStack Keystone.
Kay discovered that OpenStack Keystone incorrectly handled the ec2tokens
and s3tokens APIs. A remote attacker could possibly use this issue to
obtain unauthorized access and escalate privileges. (CVE-2025-65073)
It was discovered that OpenStack Keystone only validated the first 72
bytes of an application secret. An attacker could possibly use this issue
to bypass password complexity. (CVE-2021-3563)
It was discovered that OpenStack Keystone had a time lag before a token
should be revoked by the security policy. A remote administrator could use
this issue to maintain access for longer than expected. (CVE-2022-2447)
Instructions: In general, a standard system update will make all
Red Hat
Keystone: Verification of application credentials is silently length-limited
vendor_redhat·2021-02-17·CVSS 7.4
CVE-2021-3563 [HIGH] CWE-863 Keystone: Verification of application credentials is silently length-limited
Keystone: Verification of application credentials is silently length-limited
A flaw was found in openstack-keystone. Only the first 72 characters of an application secret are verified allowing attackers bypass some password complexity which administrators may be counting on. The highest threat from this vulnerability is to data confidentiality and integrity.
A flaw was found in openstack-keystone. Only the first 72 characters of an application secret are verified allowing attackers bypass some password complexity which administrators may be counting on. The highest threat from this vulnerability is to data confidentiality and integrity.
Package: openstack-keystone (Red Hat OpenStack Platform 10 (Newton)) - Out of support scope
Package: openstack-keystone (Red Hat OpenStack Platform 13
Debian
CVE-2021-3563: keystone - A flaw was found in openstack-keystone. Only the first 72 characters of an appli...
vendor_debian·2021·CVSS 7.4
CVE-2021-3563 [HIGH] CVE-2021-3563: keystone - A flaw was found in openstack-keystone. Only the first 72 characters of an appli...
A flaw was found in openstack-keystone. Only the first 72 characters of an application secret are verified allowing attackers bypass some password complexity which administrators may be counting on. The highest threat from this vulnerability is to data confidentiality and integrity.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 2:23.0.0-3)
sid: resolved (fixed in 2:23.0.0-3)
trixie: resolved (fixed in 2:23.0.0-3)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://access.redhat.com/security/cve/CVE-2021-3563https://bugs.launchpad.net/ossa/+bug/1901891https://bugzilla.redhat.com/show_bug.cgi?id=1962908https://lists.debian.org/debian-lts-announce/2024/01/msg00007.htmlhttps://security-tracker.debian.org/tracker/CVE-2021-3563https://access.redhat.com/security/cve/CVE-2021-3563https://bugs.launchpad.net/ossa/+bug/1901891https://bugzilla.redhat.com/show_bug.cgi?id=1962908https://lists.debian.org/debian-lts-announce/2024/01/msg00007.htmlhttps://security-tracker.debian.org/tracker/CVE-2021-3563
2022-08-26
Published