-
CVSS Score
-| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| keystone | pip | < 15.0.1 | 15.0.1 |
| keystone | pip | = 16.0.0 | 16.0.1 |
The patches provided fix several issues related to EC2 credential creation and updates, particularly around how roles are handled for trusts, application credentials, and OAuth1 access tokens. The vulnerable functions are those that were directly modified to address these issues, including handling authentication, assigning unique IDs to credentials, creating and updating credentials, and managing roles for application credentials. These changes indicate where the vulnerability existed and how it was mitigated.
Ongoing coverage of React2Shell