CVE-2013-2104Use of a Key Past its Expiration Date in Python-keystoneclient

Severity
5.5MEDIUMNVD
EPSS
0.8%
top 26.46%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 21
Latest updateMay 17

Description

python-keystoneclient before 0.2.4, as used in OpenStack Keystone (Folsom), does not properly check expiry for PKI tokens, which allows remote authenticated users to (1) retain use of a token after it has expired, or (2) use a revoked token once it expires.

CVSS vector

AV:N/AC:L/C:N/I:P/A:PExploitability: 8.0 | Impact: 4.9

Affected Packages1 packages

🔴Vulnerability Details

4
OSV
python-keystoneclient missing expiration check in PKI token validation2022-05-17
GHSA
python-keystoneclient missing expiration check in PKI token validation2022-05-17
CVEList
CVE-2013-2104: python-keystoneclient before 02014-01-21
OSV
CVE-2013-2104: python-keystoneclient before 02014-01-21

📋Vendor Advisories

4
Ubuntu
OpenStack Keystone vulnerabilities2013-06-14
Ubuntu
python-keystoneclient vulnerability2013-06-03
Red Hat
Keystone: Missing expiration check in Keystone PKI token validation2013-05-28
Debian
CVE-2013-2104: keystone - python-keystoneclient before 0.2.4, as used in OpenStack Keystone (Folsom), does...2013

💬Community

5
Bugzilla
CVE-2013-2104 OpenStack Keystoneclient: Missing expiration check in Keystone PKI token validation [fedora-19]2013-06-04
Bugzilla
CVE-2013-2104 OpenStack Keystone: Missing expiration check in Keystone PKI token validation [epel-6]2013-06-04
Bugzilla
CVE-2013-2104 OpenStack Keystone: Missing expiration check in Keystone PKI token validation [epel-6]2013-05-29
Bugzilla
CVE-2013-2104 OpenStack Keystone: Missing expiration check in Keystone PKI token validation [fedora-18]2013-05-29
Bugzilla
CVE-2013-2104 OpenStack Keystone: Missing expiration check in Keystone PKI token validation2013-05-21
CVE-2013-2104 — Use of a Key Past its Expiration Date | cvebase