Executive brief
OpenStack Keystone, the identity service for OpenStack cloud environments, contains a flaw in how it handles login sessions for users authenticated via external identity providers (like SAML or OpenID Connect). When these users switch between different projects or roles, the system incorrectly resets their session timer instead of keeping the original expiration date. This allows a user to stay logged in indefinitely by repeatedly switching roles, potentially maintaining access to cloud resources even after their corporate account has been disabled or revoked.
Technical details
A vulnerability in OpenStack Keystone's federated authentication plugin allows for session lifetime extension. When a federated user (SAML2/OIDC) performs a token rescope via 'POST /v3/auth/tokens', the 'handle_scoped_token()' function in 'keystone/auth/plugins/mapped.py' fails to include the 'expires_at' attribute in the response data. Consequently, the token provider defaults to a fresh Time-To-Live (TTL) for the new token rather than inheriting the remaining lifespan of the original token. An authenticated attacker can exploit this by repeatedly rescoping their token before it expires to bypass operator-configured session limits and maintain access after upstream revocation. This issue is fixed in versions 27.0.2, 28.0.2, and 29.0.2.
Affected products
- OpenStack Keystone >= 14.0.0, < 27.0.2; >= 28.0.0, < 28.0.2; >= 29.0.0, < 29.0.2
Timeline
- 2026-04-26: disclosed: Bug reported to OpenStack Launchpad
- 2026-05-28: advisory: OSSA-2026-015 and GHSA published
- 2026-05-28: patched: Patched versions released