Grzegorz Grasza discovered a vulnerability in the Openstack middleware to provide authentication and authorization features to web services other than Keystone: If an external OAuth provider is configured, authentication headers are insufficiently sanitised, which could result in privilege escalation or user impersonation.
The oldstable distribution (bookworm) is not affected.
https://security-tracker.debian.org/tracker/DSA-6104-1
Continue reading...
The oldstable distribution (bookworm) is not affected.
https://security-tracker.debian.org/tracker/DSA-6104-1
Continue reading...

