Skip to content

Commit c84d639

Browse files
committed
Fix link to yaook security advisory.
Thanks, @horazont! Signed-off-by: Kurt Garloff <kurt@garloff.de>
1 parent 0799d68 commit c84d639

1 file changed

Lines changed: 2 additions & 2 deletions

File tree

blog/2026-05-28-keystone.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -28,7 +28,7 @@ The core issues are:
2828

2929
- **Cross-Project EC2 Credentials (CVE-2026-43001):** Application credentials
3030
scoped to one project could be used to create EC2-style credentials for a
31-
different project, enabling lateral movement across tenant boundaries.
31+
different project, enabling lateral movement across tenant boundaries.
3232

3333
- **Federated Token Rescoping (CVE-2026-44394):** In SAML2/OIDC deployments,
3434
federated users can maintain access indefinitely by repeatedly rescoping
@@ -74,7 +74,7 @@ functionality for services like Heat or image uploads.
7474
The SCS ecosystem software providers are providing fixed Keystone images:
7575

7676
- [OSISM](https://osism.tech/docs/appendix/security/ossa-2026-015)
77-
- [yaook](https://yaook.cloud/security-advisories-cve-2026-33551)
77+
- [yaook](https://yaook.cloud/security-advisories-cve-2026-42998-43001-44394/)
7878

7979
## Outlook
8080

0 commit comments

Comments
 (0)