cbcvebase.
CVE-2013-2059
published 2013-05-21

CVE-2013-2059: OpenStack Identity (Keystone) Folsom 2012.2.4 and earlier, Grizzly before 2013.1.1, and Havana does not immediately revoke the authentication token when…

PriorityP335medium6CVSS 2.0
AVNACMAuSCPIPAP
EPSS
2.47%
82.7th percentile
OpenStack Identity (Keystone) Folsom 2012.2.4 and earlier, Grizzly before 2013.1.1, and Havana does not immediately revoke the authentication token when deleting a user through the Keystone v2 API, which allows remote authenticated users to retain access via the token.

Affected

8 ranges
VendorProductVersion rangeFixed in
debiankeystone< keystone 2013.1.1-2 (bookworm)keystone 2013.1.1-2 (bookworm)
openstackkeystone
openstackkeystone
openstackkeystone>= 0 < 2013.1.1-22013.1.1-2
openstackkeystone>= 0 < 2013.1.1-22013.1.1-2
openstackkeystone>= 0 < 2013.1.1-22013.1.1-2
openstackkeystone>= 0 < 2013.1.1-22013.1.1-2
openstackkeystone>= 0 < 8.0.0a08.0.0a0

CVSS provenance

nvdv2.06.0MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:P
osv6.0MEDIUM
vendor_debian6.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.