CVE-2013-2059
published 2013-05-21CVE-2013-2059: OpenStack Identity (Keystone) Folsom 2012.2.4 and earlier, Grizzly before 2013.1.1, and Havana does not immediately revoke the authentication token when…
PriorityP335medium6CVSS 2.0
AVNACMAuSCPIPAP
EPSS
2.47%
82.7th percentile
OpenStack Identity (Keystone) Folsom 2012.2.4 and earlier, Grizzly before 2013.1.1, and Havana does not immediately revoke the authentication token when deleting a user through the Keystone v2 API, which allows remote authenticated users to retain access via the token.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | keystone | < keystone 2013.1.1-2 (bookworm) | keystone 2013.1.1-2 (bookworm) |
| openstack | keystone | — | — |
| openstack | keystone | — | — |
| openstack | keystone | >= 0 < 2013.1.1-2 | 2013.1.1-2 |
| openstack | keystone | >= 0 < 2013.1.1-2 | 2013.1.1-2 |
| openstack | keystone | >= 0 < 2013.1.1-2 | 2013.1.1-2 |
| openstack | keystone | >= 0 < 2013.1.1-2 | 2013.1.1-2 |
| openstack | keystone | >= 0 < 8.0.0a0 | 8.0.0a0 |
CVSS provenance
nvdv2.06.0MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:P
osv6.0MEDIUM
vendor_debian6.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
OpenStack Identity (Keystone) improper revoking of the authentication token when deleting a user
ghsa·2022-05-17
CVE-2013-2059 [MEDIUM] CWE-287 OpenStack Identity (Keystone) improper revoking of the authentication token when deleting a user
OpenStack Identity (Keystone) improper revoking of the authentication token when deleting a user
OpenStack Identity (Keystone) Folsom 2012.2.4 and earlier, Grizzly before 2013.1.1, and Havana does not immediately revoke the authentication token when deleting a user through the Keystone v2 API, which allows remote authenticated users to retain access via the token.
OSV
OpenStack Identity (Keystone) improper revoking of the authentication token when deleting a user
osv·2022-05-17
CVE-2013-2059 [MEDIUM] OpenStack Identity (Keystone) improper revoking of the authentication token when deleting a user
OpenStack Identity (Keystone) improper revoking of the authentication token when deleting a user
OpenStack Identity (Keystone) Folsom 2012.2.4 and earlier, Grizzly before 2013.1.1, and Havana does not immediately revoke the authentication token when deleting a user through the Keystone v2 API, which allows remote authenticated users to retain access via the token.
OSV
CVE-2013-2059: OpenStack Identity (Keystone) Folsom 2012
osv·2013-05-21·CVSS 6.0
CVE-2013-2059 [MEDIUM] CVE-2013-2059: OpenStack Identity (Keystone) Folsom 2012
OpenStack Identity (Keystone) Folsom 2012.2.4 and earlier, Grizzly before 2013.1.1, and Havana does not immediately revoke the authentication token when deleting a user through the Keystone v2 API, which allows remote authenticated users to retain access via the token.
Ubuntu
OpenStack Keystone vulnerability
vendor_ubuntu·2013-05-16
CVE-2013-2059 OpenStack Keystone vulnerability
Title: OpenStack Keystone vulnerability
Summary: Keystone would allow unintended access over the network.
Sam Stoelinga discovered that Keystone would not immediately invalidate
tokens when deleting users via the v2 API. A deleted user would be able to
continue to use resources until the token lifetime expired.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2013-2059: keystone - OpenStack Identity (Keystone) Folsom 2012.2.4 and earlier, Grizzly before 2013.1...
vendor_debian·2013·CVSS 6.0
CVE-2013-2059 [MEDIUM] CVE-2013-2059: keystone - OpenStack Identity (Keystone) Folsom 2012.2.4 and earlier, Grizzly before 2013.1...
OpenStack Identity (Keystone) Folsom 2012.2.4 and earlier, Grizzly before 2013.1.1, and Havana does not immediately revoke the authentication token when deleting a user through the Keystone v2 API, which allows remote authenticated users to retain access via the token.
Scope: local
bookworm: resolved (fixed in 2013.1.1-2)
bullseye: resolved (fixed in 2013.1.1-2)
forky: resolved (fixed in 2013.1.1-2)
sid: resolved (fixed in 2013.1.1-2)
trixie: resolved (fixed in 2013.1.1-2)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-2059 OpenStack Keystone: tokens not immediately invalidated when user is deleted [fedora-all]
bugzilla·2013-05-10·CVSS 6.0
CVE-2013-2059 [MEDIUM] CVE-2013-2059 OpenStack Keystone: tokens not immediately invalidated when user is deleted [fedora-all]
CVE-2013-2059 OpenStack Keystone: tokens not immediately invalidated when user is deleted [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Pl
Bugzilla
CVE-2013-2059 OpenStack Keystone: tokens not immediately invalidated when user is deleted [epel-6]
bugzilla·2013-05-10·CVSS 6.0
CVE-2013-2059 [MEDIUM] CVE-2013-2059 OpenStack Keystone: tokens not immediately invalidated when user is deleted [epel-6]
CVE-2013-2059 OpenStack Keystone: tokens not immediately invalidated when user is deleted [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
e
Bugzilla
CVE-2013-2059 OpenStack Keystone: tokens not immediately invalidated when user is deleted
bugzilla·2013-05-06·CVSS 6.0
CVE-2013-2059 [MEDIUM] CVE-2013-2059 OpenStack Keystone: tokens not immediately invalidated when user is deleted
CVE-2013-2059 OpenStack Keystone: tokens not immediately invalidated when user is deleted
Thierry Carrez reports:
Title: Keystone tokens not immediately invalidated when user is deleted
Reporter: Sam Stoelinga
Products: Keystone
Affects: Folsom, Grizzly
Description:
Sam Stoelinga reported a vulnerability in Keystone. When users are
deleted through Keystone v2 API, existing tokens for those users are not
immediately invalidated and remain valid for the duration of the token's
life (by default, up to 24 hours). This may result in users retaining
access when the administrator of the system thought them disabled. You
can workaround this issue by disabling a user before deleting it: in
that case the tokens belonging to the disabled user are immediately
invalidated. Keystone setups using the
http://lists.fedoraproject.org/pipermail/package-announce/2013-May/105916.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-May/106220.htmlhttp://lists.opensuse.org/opensuse-updates/2013-06/msg00085.htmlhttp://osvdb.org/93134http://secunia.com/advisories/53326http://secunia.com/advisories/53339http://www.openwall.com/lists/oss-security/2013/05/09/3http://www.openwall.com/lists/oss-security/2013/05/09/4http://www.securityfocus.com/bid/59787https://bugs.launchpad.net/keystone/+bug/1166670https://exchange.xforce.ibmcloud.com/vulnerabilities/84135http://lists.fedoraproject.org/pipermail/package-announce/2013-May/105916.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-May/106220.htmlhttp://lists.opensuse.org/opensuse-updates/2013-06/msg00085.htmlhttp://osvdb.org/93134http://secunia.com/advisories/53326http://secunia.com/advisories/53339http://www.openwall.com/lists/oss-security/2013/05/09/3http://www.openwall.com/lists/oss-security/2013/05/09/4http://www.securityfocus.com/bid/59787https://bugs.launchpad.net/keystone/+bug/1166670https://exchange.xforce.ibmcloud.com/vulnerabilities/84135
2013-05-21
Published