Keystone

Vendor:

First CVE: Jul 31, 2012 · Active for 13 years

46
Total CVEs
More Total CVEs than 97% of tracked products
3.8
Avg CVEs / Year
Higher CVE frequency than 83% of tracked products
6.2
Avg CVSS
Higher Avg CVSS than 24% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Keystone over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 31, 2012
13 years ago
Most Recent CVE
May 28, 2026
57 days ago

CVE Severity & Scoring

Keystone46 CVEs
All CVEs352,231 CVEs
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network22 (47.8%)
Unknown24 (52.2%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low13 (28.3%)
High9 (19.6%)
Unknown24 (52.2%)
User Interaction
None22 (47.8%)
Unknown24 (52.2%)
Required0 (0.0%)
Privileges Required
Low15 (32.6%)
High1 (2.2%)
None6 (13.0%)
Unknown24 (52.2%)

Top CVEs

Signals from CVEs in this product scope (46 CVEs).

46 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
An issue was discovered in OpenStack Keystone before 29.0.2. POST /v3/credentials did not validate that the caller-supplied project_id for an EC2-type credential matched the projec
May 1, 20268.035NONO
An issue was discovered in OpenStack Keystone before 29.0.2. When combined with an application credential impersonation vulnerability, an attacker with the member role on a project
May 28, 20268.834NONO
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone RBAC policy enforcer in enforce_call unconditionally merges the raw JSON request body into the policy enfo
May 28, 20268.834NONO
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone application credential authentication plugin does not verify that the user supplied in the authentication
May 28, 20268.831NONO
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone federated token rescoping mechanism does not propagate the original token's expiry to the newly issued tok
May 28, 20268.129NONO
OpenStack Keystone 15.0.0 and 16.0.0 is affected by Data Leakage in the list credentials API. Any user with a role on a project is able to list any credentials with the /v3/credent
Dec 9, 20198.827NONO
In OpenStack Keystone before 28.0.1, the LDAP identity backend does not convert the user enabled attribute to a boolean when the user_enabled_invert configuration option is False (
Apr 14, 20267.726NONO
OpenStack Keystone before 26.0.1, 27.0.0, and 28.0.0 allows a /v3/ec2tokens or /v3/s3tokens request with a valid AWS Signature to provide Keystone authorization.
Nov 17, 20257.524NONO
OpenStack Keystone 10.x through 16.x before 16.0.2, 17.x before 17.0.1, 18.x before 18.0.1, and 19.x before 19.0.1 allows information disclosure during account locking (related to
Aug 6, 20217.524NONO
OpenStack Keystone: extremely long passwords can crash Keystone by exhausting stack space
Nov 12, 20197.524NONO

Exploit Exposure

Signals from CVEs in this product scope (46 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (46 CVEs).

Media Mentions

Signals from CVEs in this product scope (46 CVEs).

Top CNAs Publishing CVEs For Keystone

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
juno-234.91.5%00
juno-134.91.5%00
29.0.015.30.2%00
28.0.015.30.2%00
27.0.015.30.2%00
2014.1.234.91.5%00
2014.134.91.5%00
2013.2.317.83.2%00
2013.2.226.42.3%00
2013.2.117.83.2%00
2013.217.83.2%00
2013.1.415.01.4%00
2013.1.335.92.4%00
2013.1.235.92.4%00
2013.1.145.02.0%00
2013.165.82.4%00
201315.91.0%00
2012.2.415.02.7%00
2012.2.315.02.7%00
2012.2.215.02.7%00