@@ -28,7 +28,7 @@ The core issues are:
2828
2929- ** Cross-Project EC2 Credentials (CVE-2026 -43001):** Application credentials
3030 scoped to one project could be used to create EC2-style credentials for a
31- i different project, enabling lateral movement across tenant boundaries.
31+ different project, enabling lateral movement across tenant boundaries.
3232
3333- ** Federated Token Rescoping (CVE-2026 -44394):** In SAML2/OIDC deployments,
3434 federated users can maintain access indefinitely by repeatedly rescoping
@@ -71,7 +71,7 @@ the fix for CVE-2026-42999 modifies the trust policy structure. This may
7171require manual updates to your custom policies to ensure continued
7272functionality for services like Heat or image uploads.
7373
74- The SCS ecosystem software providers are providing fixed keystone images:
74+ The SCS ecosystem software providers are providing fixed Keystone images:
7575
7676- [ OSISM] ( https://osism.tech/docs/appendix/security/ossa-2026-015 )
7777- [ yaook] ( https://yaook.cloud/security-advisories-cve-2026-33551 )
@@ -110,8 +110,8 @@ them down in deployment.
110110
111111The author would like to thank Boris Bobrov, Tim Shepherd, Erichen, and Artem
112112Goncharov for their work in discovering and reporting these critical
113- vulnerabilities and the OpenStack Vulnerabilty Mangement Team for handling
114- and coordinating this and the OpenStack keystone upstream developers for
113+ vulnerabilities and the OpenStack Vulnerability Management Team for handling
114+ and coordinating this and the OpenStack Keystone upstream developers for
115115addressing the issues.
116116
117117## Sovereign Cloud Stack Security Contact
0 commit comments