{
  "document": {
    "aggregate_severity": {
      "namespace": "https://access.redhat.com/security/updates/classification/",
      "text": "Important"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "Copyright © Red Hat, Inc. All rights reserved.",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://access.redhat.com/security/team/contact/",
      "issuing_authority": "Red Hat Product Security is responsible for vulnerability handling across all Red Hat products and services.",
      "name": "Red Hat Product Security",
      "namespace": "https://www.redhat.com"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-43001.json"
      }
    ],
    "title": "OpenStack Keystone: OpenStack Keystone: Unauthorized cross-project access due to improper validation in EC2 credential creation",
    "tracking": {
      "current_release_date": "2026-07-15T12:11:28+00:00",
      "generator": {
        "date": "2026-07-15T12:11:28+00:00",
        "engine": {
          "name": "Red Hat SDEngine",
          "version": "5.3.2"
        }
      },
      "id": "CVE-2026-43001",
      "initial_release_date": "2026-05-01T00:00:00+00:00",
      "revision_history": [
        {
          "date": "2026-05-01T00:00:00+00:00",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-06-02T15:30:09+00:00",
          "number": "2",
          "summary": "Current version"
        },
        {
          "date": "2026-07-15T12:11:28+00:00",
          "number": "3",
          "summary": "Last generated version"
        }
      ],
      "status": "final",
      "version": "3"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat OpenStack Platform 13 (Queens)",
                "product": {
                  "name": "Red Hat OpenStack Platform 13 (Queens)",
                  "product_id": "red_hat_openstack_platform_13_(queens)",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:openstack:13"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat OpenStack Platform 13 (Queens)"
          },
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat OpenStack Platform 16.2",
                "product": {
                  "name": "Red Hat OpenStack Platform 16.2",
                  "product_id": "red_hat_openstack_platform_16.2",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:openstack:16.2"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat OpenStack Platform 16.2"
          },
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat OpenStack Platform 17.1",
                "product": {
                  "name": "Red Hat OpenStack Platform 17.1",
                  "product_id": "red_hat_openstack_platform_17.1",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:openstack:17.1"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat OpenStack Platform 17.1"
          },
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat OpenStack Platform 18.0",
                "product": {
                  "name": "Red Hat OpenStack Platform 18.0",
                  "product_id": "red_hat_openstack_platform_18.0",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:openstack:18.0"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat OpenStack Platform 18.0"
          },
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat OpenStack Services on OpenShift 18.0",
                "product": {
                  "name": "Red Hat OpenStack Services on OpenShift 18.0",
                  "product_id": "9Base-RHOSO-18.0",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:openstack:18.0::el9"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat OpenStack Services on OpenShift"
          },
          {
            "category": "product_version",
            "name": "rhosp13/openstack-keystone",
            "product": {
              "name": "rhosp13/openstack-keystone",
              "product_id": "rhosp13/openstack-keystone",
              "product_identification_helper": {
                "purl": "pkg:oci/openstack-keystone?repository_url=registry.redhat.io/rhosp13/openstack-keystone"
              }
            }
          },
          {
            "category": "product_version",
            "name": "openstack-keystone.src",
            "product": {
              "name": "openstack-keystone.src",
              "product_id": "openstack-keystone.src",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/openstack-keystone?arch=src"
              }
            }
          },
          {
            "category": "product_version",
            "name": "python3-keystone",
            "product": {
              "name": "python3-keystone",
              "product_id": "python3-keystone",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/python3-keystone"
              }
            }
          },
          {
            "category": "product_version",
            "name": "rhosp-rhel8/openstack-keystone",
            "product": {
              "name": "rhosp-rhel8/openstack-keystone",
              "product_id": "rhosp-rhel8/openstack-keystone",
              "product_identification_helper": {
                "purl": "pkg:oci/openstack-keystone?repository_url=registry.redhat.io/rhosp-rhel8/openstack-keystone"
              }
            }
          },
          {
            "category": "product_version",
            "name": "openstack-keystone",
            "product": {
              "name": "openstack-keystone",
              "product_id": "openstack-keystone",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/openstack-keystone"
              }
            }
          },
          {
            "category": "product_version",
            "name": "rhosp-rhel9/openstack-keystone",
            "product": {
              "name": "rhosp-rhel9/openstack-keystone",
              "product_id": "rhosp-rhel9/openstack-keystone",
              "product_identification_helper": {
                "purl": "pkg:oci/openstack-keystone?repository_url=registry.redhat.io/rhosp-rhel9/openstack-keystone"
              }
            }
          },
          {
            "category": "product_version",
            "name": "rhoso/openstack-keystone-rhel9",
            "product": {
              "name": "rhoso/openstack-keystone-rhel9",
              "product_id": "rhoso/openstack-keystone-rhel9",
              "product_identification_helper": {
                "purl": "pkg:oci/openstack-keystone-rhel9?repository_url=registry.redhat.io/rhoso/openstack-keystone-rhel9"
              }
            }
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "openstack-keystone-1:23.0.3-18.0.20260610133808.9e3dfb4.el9ost.src",
                "product": {
                  "name": "openstack-keystone-1:23.0.3-18.0.20260610133808.9e3dfb4.el9ost.src",
                  "product_id": "openstack-keystone-1:23.0.3-18.0.20260610133808.9e3dfb4.el9ost.src",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/openstack-keystone@23.0.3-18.0.20260610133808.9e3dfb4.el9ost?arch=src&epoch=1"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "src"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "openstack-keystone-1:23.0.3-18.0.20260610133808.9e3dfb4.el9ost.noarch",
                "product": {
                  "name": "openstack-keystone-1:23.0.3-18.0.20260610133808.9e3dfb4.el9ost.noarch",
                  "product_id": "openstack-keystone-1:23.0.3-18.0.20260610133808.9e3dfb4.el9ost.noarch",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/openstack-keystone@23.0.3-18.0.20260610133808.9e3dfb4.el9ost?arch=noarch&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "python3-keystone-1:23.0.3-18.0.20260610133808.9e3dfb4.el9ost.noarch",
                "product": {
                  "name": "python3-keystone-1:23.0.3-18.0.20260610133808.9e3dfb4.el9ost.noarch",
                  "product_id": "python3-keystone-1:23.0.3-18.0.20260610133808.9e3dfb4.el9ost.noarch",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/python3-keystone@23.0.3-18.0.20260610133808.9e3dfb4.el9ost?arch=noarch&epoch=1"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "noarch"
          }
        ],
        "category": "vendor",
        "name": "Red Hat"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openstack-keystone-1:23.0.3-18.0.20260610133808.9e3dfb4.el9ost.noarch as a component of Red Hat OpenStack Services on OpenShift 18.0",
          "product_id": "9Base-RHOSO-18.0:openstack-keystone-1:23.0.3-18.0.20260610133808.9e3dfb4.el9ost.noarch"
        },
        "product_reference": "openstack-keystone-1:23.0.3-18.0.20260610133808.9e3dfb4.el9ost.noarch",
        "relates_to_product_reference": "9Base-RHOSO-18.0"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openstack-keystone-1:23.0.3-18.0.20260610133808.9e3dfb4.el9ost.src as a component of Red Hat OpenStack Services on OpenShift 18.0",
          "product_id": "9Base-RHOSO-18.0:openstack-keystone-1:23.0.3-18.0.20260610133808.9e3dfb4.el9ost.src"
        },
        "product_reference": "openstack-keystone-1:23.0.3-18.0.20260610133808.9e3dfb4.el9ost.src",
        "relates_to_product_reference": "9Base-RHOSO-18.0"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "python3-keystone-1:23.0.3-18.0.20260610133808.9e3dfb4.el9ost.noarch as a component of Red Hat OpenStack Services on OpenShift 18.0",
          "product_id": "9Base-RHOSO-18.0:python3-keystone-1:23.0.3-18.0.20260610133808.9e3dfb4.el9ost.noarch"
        },
        "product_reference": "python3-keystone-1:23.0.3-18.0.20260610133808.9e3dfb4.el9ost.noarch",
        "relates_to_product_reference": "9Base-RHOSO-18.0"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rhosp13/openstack-keystone as a component of Red Hat OpenStack Platform 13 (Queens)",
          "product_id": "red_hat_openstack_platform_13_(queens):rhosp13/openstack-keystone"
        },
        "product_reference": "rhosp13/openstack-keystone",
        "relates_to_product_reference": "red_hat_openstack_platform_13_(queens)"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openstack-keystone.src as a component of Red Hat OpenStack Platform 16.2",
          "product_id": "red_hat_openstack_platform_16.2:openstack-keystone.src"
        },
        "product_reference": "openstack-keystone.src",
        "relates_to_product_reference": "red_hat_openstack_platform_16.2"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "python3-keystone as a component of Red Hat OpenStack Platform 16.2",
          "product_id": "red_hat_openstack_platform_16.2:python3-keystone"
        },
        "product_reference": "python3-keystone",
        "relates_to_product_reference": "red_hat_openstack_platform_16.2"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rhosp-rhel8/openstack-keystone as a component of Red Hat OpenStack Platform 16.2",
          "product_id": "red_hat_openstack_platform_16.2:rhosp-rhel8/openstack-keystone"
        },
        "product_reference": "rhosp-rhel8/openstack-keystone",
        "relates_to_product_reference": "red_hat_openstack_platform_16.2"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openstack-keystone as a component of Red Hat OpenStack Platform 17.1",
          "product_id": "red_hat_openstack_platform_17.1:openstack-keystone"
        },
        "product_reference": "openstack-keystone",
        "relates_to_product_reference": "red_hat_openstack_platform_17.1"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openstack-keystone.src as a component of Red Hat OpenStack Platform 17.1",
          "product_id": "red_hat_openstack_platform_17.1:openstack-keystone.src"
        },
        "product_reference": "openstack-keystone.src",
        "relates_to_product_reference": "red_hat_openstack_platform_17.1"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "python3-keystone as a component of Red Hat OpenStack Platform 17.1",
          "product_id": "red_hat_openstack_platform_17.1:python3-keystone"
        },
        "product_reference": "python3-keystone",
        "relates_to_product_reference": "red_hat_openstack_platform_17.1"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rhosp-rhel9/openstack-keystone as a component of Red Hat OpenStack Platform 17.1",
          "product_id": "red_hat_openstack_platform_17.1:rhosp-rhel9/openstack-keystone"
        },
        "product_reference": "rhosp-rhel9/openstack-keystone",
        "relates_to_product_reference": "red_hat_openstack_platform_17.1"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rhoso/openstack-keystone-rhel9 as a component of Red Hat OpenStack Platform 18.0",
          "product_id": "red_hat_openstack_platform_18.0:rhoso/openstack-keystone-rhel9"
        },
        "product_reference": "rhoso/openstack-keystone-rhel9",
        "relates_to_product_reference": "red_hat_openstack_platform_18.0"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-43001",
      "cwe": {
        "id": "CWE-1288",
        "name": "Improper Validation of Consistency within Input"
      },
      "discovery_date": "2026-05-01T09:00:55.408726+00:00",
      "flags": [
        {
          "label": "component_not_present",
          "product_ids": [
            "red_hat_openstack_platform_13_(queens):rhosp13/openstack-keystone",
            "red_hat_openstack_platform_16.2:rhosp-rhel8/openstack-keystone",
            "red_hat_openstack_platform_17.1:rhosp-rhel9/openstack-keystone",
            "red_hat_openstack_platform_18.0:rhoso/openstack-keystone-rhel9"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Red Hat Bugzilla ID",
          "text": "2464305"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in OpenStack Keystone. An attacker holding an unrestricted application credential could exploit a vulnerability in the POST /v3/credentials endpoint where the caller-supplied project_id for an EC2-type credential was not validated against the project of the authenticating application credential. This allows the attacker to create an EC2 credential targeting a different project. Subsequently, a /v3/ec2tokens exchange would issue a Keystone token scoped to the targeted project, enabling unauthorized cross-project access and lateral movement within the credential owner's role footprint.",
          "title": "Vulnerability description"
        },
        {
          "category": "summary",
          "text": "OpenStack Keystone: OpenStack Keystone: Unauthorized cross-project access due to improper validation in EC2 credential creation",
          "title": "Vulnerability summary"
        },
        {
          "category": "other",
          "text": "This flaw in OpenStack Keystone allows an attacker with an unrestricted application credential to bypass project isolation. By exploiting improper validation during EC2 credential creation, an attacker can gain unauthorized access and move laterally between projects within a Red Hat OpenStack Platform deployment, compromising multi-tenant security. If the roles from the original project the attacker holds a credential are compatible with the roles in the project the attacker is targeting, the attacker can perform the same actions granted permission from the initial project in the targeted project. Depending on the level of privileges the attacker has that means a high impact for confidentiality, availability and integrity.",
          "title": "Statement"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "9Base-RHOSO-18.0:openstack-keystone-1:23.0.3-18.0.20260610133808.9e3dfb4.el9ost.noarch",
          "9Base-RHOSO-18.0:openstack-keystone-1:23.0.3-18.0.20260610133808.9e3dfb4.el9ost.src",
          "9Base-RHOSO-18.0:python3-keystone-1:23.0.3-18.0.20260610133808.9e3dfb4.el9ost.noarch"
        ],
        "known_affected": [
          "red_hat_openstack_platform_16.2:openstack-keystone.src",
          "red_hat_openstack_platform_16.2:python3-keystone",
          "red_hat_openstack_platform_17.1:openstack-keystone",
          "red_hat_openstack_platform_17.1:openstack-keystone.src",
          "red_hat_openstack_platform_17.1:python3-keystone"
        ],
        "known_not_affected": [
          "red_hat_openstack_platform_13_(queens):rhosp13/openstack-keystone",
          "red_hat_openstack_platform_16.2:rhosp-rhel8/openstack-keystone",
          "red_hat_openstack_platform_17.1:rhosp-rhel9/openstack-keystone",
          "red_hat_openstack_platform_18.0:rhoso/openstack-keystone-rhel9"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2026-43001"
        },
        {
          "category": "external",
          "summary": "RHBZ#2464305",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2464305"
        },
        {
          "category": "external",
          "summary": "https://www.cve.org/CVERecord?id=CVE-2026-43001",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-43001"
        },
        {
          "category": "external",
          "summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-43001",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-43001"
        },
        {
          "category": "external",
          "summary": "https://bugs.launchpad.net/keystone/+bug/2149775",
          "url": "https://bugs.launchpad.net/keystone/+bug/2149775"
        },
        {
          "category": "external",
          "summary": "https://review.opendev.org/c/openstack/keystone/+/985804",
          "url": "https://review.opendev.org/c/openstack/keystone/+/985804"
        }
      ],
      "release_date": "2026-05-01T00:00:00+00:00",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-07-15T09:52:02+00:00",
          "details": "For details on how to apply this update, which includes the changes\ndescribed in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258",
          "product_ids": [
            "9Base-RHOSO-18.0:openstack-keystone-1:23.0.3-18.0.20260610133808.9e3dfb4.el9ost.noarch",
            "9Base-RHOSO-18.0:openstack-keystone-1:23.0.3-18.0.20260610133808.9e3dfb4.el9ost.src",
            "9Base-RHOSO-18.0:python3-keystone-1:23.0.3-18.0.20260610133808.9e3dfb4.el9ost.noarch"
          ],
          "url": "https://access.redhat.com/errata/RHSA-2026:39808"
        },
        {
          "category": "workaround",
          "details": "To reduce exposure, ensure that OpenStack application credentials are created with the most restrictive scope possible, limiting their permissions to only what is essential for their intended function. If EC2 credentials are not actively used within your OpenStack deployment, consider disabling the EC2 credential API endpoint in Keystone to prevent unauthorized creation of cross-project EC2 credentials. Refer to the OpenStack Keystone administration guide for detailed instructions on managing application credential scopes and disabling API endpoints. Any changes to Keystone configuration may require a service restart to take effect.",
          "product_ids": [
            "9Base-RHOSO-18.0:openstack-keystone-1:23.0.3-18.0.20260610133808.9e3dfb4.el9ost.noarch",
            "9Base-RHOSO-18.0:openstack-keystone-1:23.0.3-18.0.20260610133808.9e3dfb4.el9ost.src",
            "9Base-RHOSO-18.0:python3-keystone-1:23.0.3-18.0.20260610133808.9e3dfb4.el9ost.noarch",
            "red_hat_openstack_platform_16.2:openstack-keystone.src",
            "red_hat_openstack_platform_16.2:python3-keystone",
            "red_hat_openstack_platform_17.1:openstack-keystone",
            "red_hat_openstack_platform_17.1:openstack-keystone.src",
            "red_hat_openstack_platform_17.1:python3-keystone"
          ]
        },
        {
          "category": "none_available",
          "details": "Affected",
          "product_ids": [
            "red_hat_openstack_platform_16.2:openstack-keystone.src",
            "red_hat_openstack_platform_16.2:python3-keystone",
            "red_hat_openstack_platform_17.1:openstack-keystone",
            "red_hat_openstack_platform_17.1:openstack-keystone.src",
            "red_hat_openstack_platform_17.1:python3-keystone"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.0,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "HIGH",
            "scope": "CHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "9Base-RHOSO-18.0:openstack-keystone-1:23.0.3-18.0.20260610133808.9e3dfb4.el9ost.noarch",
            "9Base-RHOSO-18.0:openstack-keystone-1:23.0.3-18.0.20260610133808.9e3dfb4.el9ost.src",
            "9Base-RHOSO-18.0:python3-keystone-1:23.0.3-18.0.20260610133808.9e3dfb4.el9ost.noarch",
            "red_hat_openstack_platform_13_(queens):rhosp13/openstack-keystone",
            "red_hat_openstack_platform_16.2:openstack-keystone.src",
            "red_hat_openstack_platform_16.2:python3-keystone",
            "red_hat_openstack_platform_16.2:rhosp-rhel8/openstack-keystone",
            "red_hat_openstack_platform_17.1:openstack-keystone",
            "red_hat_openstack_platform_17.1:openstack-keystone.src",
            "red_hat_openstack_platform_17.1:python3-keystone",
            "red_hat_openstack_platform_17.1:rhosp-rhel9/openstack-keystone",
            "red_hat_openstack_platform_18.0:rhoso/openstack-keystone-rhel9"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important",
          "product_ids": [
            "9Base-RHOSO-18.0:openstack-keystone-1:23.0.3-18.0.20260610133808.9e3dfb4.el9ost.noarch",
            "9Base-RHOSO-18.0:openstack-keystone-1:23.0.3-18.0.20260610133808.9e3dfb4.el9ost.src",
            "9Base-RHOSO-18.0:python3-keystone-1:23.0.3-18.0.20260610133808.9e3dfb4.el9ost.noarch",
            "red_hat_openstack_platform_13_(queens):rhosp13/openstack-keystone",
            "red_hat_openstack_platform_16.2:openstack-keystone.src",
            "red_hat_openstack_platform_16.2:python3-keystone",
            "red_hat_openstack_platform_16.2:rhosp-rhel8/openstack-keystone",
            "red_hat_openstack_platform_17.1:openstack-keystone",
            "red_hat_openstack_platform_17.1:openstack-keystone.src",
            "red_hat_openstack_platform_17.1:python3-keystone",
            "red_hat_openstack_platform_17.1:rhosp-rhel9/openstack-keystone",
            "red_hat_openstack_platform_18.0:rhoso/openstack-keystone-rhel9"
          ]
        }
      ],
      "title": "OpenStack Keystone: OpenStack Keystone: Unauthorized cross-project access due to improper validation in EC2 credential creation"
    }
  ]
}