cbcvebase.
CVE-2013-2104
published 2014-01-21

CVE-2013-2104: python-keystoneclient before 0.2.4, as used in OpenStack Keystone (Folsom), does not properly check expiry for PKI tokens, which allows remote authenticated…

PriorityP425medium5.5CVSS 2.0
AVNACLAuSCNIPAP
EPSS
2.06%
79.4th percentile
python-keystoneclient before 0.2.4, as used in OpenStack Keystone (Folsom), does not properly check expiry for PKI tokens, which allows remote authenticated users to (1) retain use of a token after it has expired, or (2) use a revoked token once it expires.

Affected

9 ranges
VendorProductVersion rangeFixed in
debiankeystone< python-keystoneclient 1:0.2.5-1 (bookworm)python-keystoneclient 1:0.2.5-1 (bookworm)
debianpython-keystoneclient< python-keystoneclient 1:0.2.5-1 (bookworm)python-keystoneclient 1:0.2.5-1 (bookworm)
openstackpython-keystoneclient<= 0.2.3
openstackpython-keystoneclient
openstackpython-keystoneclient>= 0 < 1:0.2.5-11:0.2.5-1
openstackpython-keystoneclient>= 0 < 1:0.2.5-11:0.2.5-1
openstackpython-keystoneclient>= 0 < 1:0.2.5-11:0.2.5-1
openstackpython-keystoneclient>= 0 < 1:0.2.5-11:0.2.5-1
openstackpython-keystoneclient>= 0 < 0.2.40.2.4

CVSS provenance

nvdv2.05.5MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:P
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.