CVE-2013-2104
published 2014-01-21CVE-2013-2104: python-keystoneclient before 0.2.4, as used in OpenStack Keystone (Folsom), does not properly check expiry for PKI tokens, which allows remote authenticated…
PriorityP425medium5.5CVSS 2.0
AVNACLAuSCNIPAP
EPSS
2.06%
79.4th percentile
python-keystoneclient before 0.2.4, as used in OpenStack Keystone (Folsom), does not properly check expiry for PKI tokens, which allows remote authenticated users to (1) retain use of a token after it has expired, or (2) use a revoked token once it expires.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | keystone | < python-keystoneclient 1:0.2.5-1 (bookworm) | python-keystoneclient 1:0.2.5-1 (bookworm) |
| debian | python-keystoneclient | < python-keystoneclient 1:0.2.5-1 (bookworm) | python-keystoneclient 1:0.2.5-1 (bookworm) |
| openstack | python-keystoneclient | <= 0.2.3 | — |
| openstack | python-keystoneclient | — | — |
| openstack | python-keystoneclient | >= 0 < 1:0.2.5-1 | 1:0.2.5-1 |
| openstack | python-keystoneclient | >= 0 < 1:0.2.5-1 | 1:0.2.5-1 |
| openstack | python-keystoneclient | >= 0 < 1:0.2.5-1 | 1:0.2.5-1 |
| openstack | python-keystoneclient | >= 0 < 1:0.2.5-1 | 1:0.2.5-1 |
| openstack | python-keystoneclient | >= 0 < 0.2.4 | 0.2.4 |
CVSS provenance
nvdv2.05.5MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:P
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
OpenStack Keystone vulnerabilities
vendor_ubuntu·2013-06-14·CVSS 5.5
CVE-2013-2104 [MEDIUM] OpenStack Keystone vulnerabilities
Title: OpenStack Keystone vulnerabilities
Summary: Keystone did not always properly verify expired PKI tokens or properly
authenticate users.
Eoghan Glynn and Alex Meade discovered that Keystone did not properly
perform expiry checks for the PKI tokens used in Keystone. If Keystone were
setup to use PKI tokens, a previously authenticated user could continue to
use a PKI token for longer than intended. This issue only affected Ubuntu
12.10 which does not use PKI tokens by default. (CVE-2013-2104)
Jose Castro Leon discovered that Keystone did not properly authenticate
users when using the LDAP backend. An attacker could obtain valid tokens
and impersonate other users by supplying an empty password. By default,
Ubuntu does not use the LDAP backend. (CVE-2013-2157)
Instructions: In general
Ubuntu
python-keystoneclient vulnerability
vendor_ubuntu·2013-06-03
CVE-2013-2104 python-keystoneclient vulnerability
Title: python-keystoneclient vulnerability
Summary: The python client library for Keystone did not properly verify expired PKI
tokens.
Eoghan Glynn and Alex Meade discovered that python-keystoneclient did not
properly perform expiry checks for the PKI tokens used in Keystone. If
Keystone were setup to use PKI tokens (the default in Ubuntu 13.04), a
previously authenticated user could continue to use a PKI token for longer
than intended.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
Keystone: Missing expiration check in Keystone PKI token validation
vendor_redhat·2013-05-28·CVSS 5.5
CVE-2013-2104 [MEDIUM] CWE-613 Keystone: Missing expiration check in Keystone PKI token validation
Keystone: Missing expiration check in Keystone PKI token validation
python-keystoneclient before 0.2.4, as used in OpenStack Keystone (Folsom), does not properly check expiry for PKI tokens, which allows remote authenticated users to (1) retain use of a token after it has expired, or (2) use a revoked token once it expires.
Debian
CVE-2013-2104: keystone - python-keystoneclient before 0.2.4, as used in OpenStack Keystone (Folsom), does...
vendor_debian·2013·CVSS 5.5
CVE-2013-2104 [MEDIUM] CVE-2013-2104: keystone - python-keystoneclient before 0.2.4, as used in OpenStack Keystone (Folsom), does...
python-keystoneclient before 0.2.4, as used in OpenStack Keystone (Folsom), does not properly check expiry for PKI tokens, which allows remote authenticated users to (1) retain use of a token after it has expired, or (2) use a revoked token once it expires.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
OSV
python-keystoneclient missing expiration check in PKI token validation
osv·2022-05-17
CVE-2013-2104 [HIGH] python-keystoneclient missing expiration check in PKI token validation
python-keystoneclient missing expiration check in PKI token validation
python-keystoneclient before 0.2.4, as used in OpenStack Keystone (Folsom), does not properly check expiry for PKI tokens, which allows remote authenticated users to (1) retain use of a token after it has expired, or (2) use a revoked token once it expires.
GHSA
python-keystoneclient missing expiration check in PKI token validation
ghsa·2022-05-17
CVE-2013-2104 [HIGH] CWE-324 python-keystoneclient missing expiration check in PKI token validation
python-keystoneclient missing expiration check in PKI token validation
python-keystoneclient before 0.2.4, as used in OpenStack Keystone (Folsom), does not properly check expiry for PKI tokens, which allows remote authenticated users to (1) retain use of a token after it has expired, or (2) use a revoked token once it expires.
OSV
CVE-2013-2104: python-keystoneclient before 0
osv·2014-01-21·CVSS 5.5
CVE-2013-2104 [MEDIUM] CVE-2013-2104: python-keystoneclient before 0
python-keystoneclient before 0.2.4, as used in OpenStack Keystone (Folsom), does not properly check expiry for PKI tokens, which allows remote authenticated users to (1) retain use of a token after it has expired, or (2) use a revoked token once it expires.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-2104 OpenStack Keystoneclient: Missing expiration check in Keystone PKI token validation [fedora-19]
bugzilla·2013-06-04·CVSS 5.5
CVE-2013-2104 [MEDIUM] CVE-2013-2104 OpenStack Keystoneclient: Missing expiration check in Keystone PKI token validation [fedora-19]
CVE-2013-2104 OpenStack Keystoneclient: Missing expiration check in Keystone PKI token validation [fedora-19]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when availab
Bugzilla
CVE-2013-2104 OpenStack Keystone: Missing expiration check in Keystone PKI token validation [epel-6]
bugzilla·2013-06-04·CVSS 5.5
CVE-2013-2104 [MEDIUM] CVE-2013-2104 OpenStack Keystone: Missing expiration check in Keystone PKI token validation [epel-6]
CVE-2013-2104 OpenStack Keystone: Missing expiration check in Keystone PKI token validation [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Bugzilla
CVE-2013-2104 OpenStack Keystone: Missing expiration check in Keystone PKI token validation [epel-6]
bugzilla·2013-05-29·CVSS 5.5
CVE-2013-2104 [MEDIUM] CVE-2013-2104 OpenStack Keystone: Missing expiration check in Keystone PKI token validation [epel-6]
CVE-2013-2104 OpenStack Keystone: Missing expiration check in Keystone PKI token validation [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Bugzilla
CVE-2013-2104 OpenStack Keystone: Missing expiration check in Keystone PKI token validation [fedora-18]
bugzilla·2013-05-29·CVSS 5.5
CVE-2013-2104 [MEDIUM] CVE-2013-2104 OpenStack Keystone: Missing expiration check in Keystone PKI token validation [fedora-18]
CVE-2013-2104 OpenStack Keystone: Missing expiration check in Keystone PKI token validation [fedora-18]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
P
Bugzilla
CVE-2013-2104 OpenStack Keystone: Missing expiration check in Keystone PKI token validation
bugzilla·2013-05-21·CVSS 5.5
CVE-2013-2104 [MEDIUM] CVE-2013-2104 OpenStack Keystone: Missing expiration check in Keystone PKI token validation
CVE-2013-2104 OpenStack Keystone: Missing expiration check in Keystone PKI token validation
Thierry Carrez ([email protected]) reports:
Title: Missing expiration check in Keystone PKI token validation
Reporter: Eoghan Glynn (Red Hat)
Products/Affects: Keystone (Folsom only), python-keystoneclient (0.2.0+)
Description:
Eoghan Glynn from Red Hat reported a vulnerability in expiry checks for
PKI tokens in the Keystone authentication middleware. Expired tokens for
authenticated users could continue to be used, potentially resulting in
the bypass of intended security policies. The effect of PKI token
revocation is also reversed when the token expires, in the sense that a
revoked token is once again treated as being valid. Only setups using
PKI tokens are affected.
Note:
The affected cod
http://lists.opensuse.org/opensuse-updates/2013-06/msg00198.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0944.htmlhttp://www.openwall.com/lists/oss-security/2013/05/28/7http://www.ubuntu.com/usn/USN-1851-1http://www.ubuntu.com/usn/USN-1875-1https://bugs.launchpad.net/python-keystoneclient/+bug/1179615http://lists.opensuse.org/opensuse-updates/2013-06/msg00198.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0944.htmlhttp://www.openwall.com/lists/oss-security/2013/05/28/7http://www.ubuntu.com/usn/USN-1851-1http://www.ubuntu.com/usn/USN-1875-1https://bugs.launchpad.net/python-keystoneclient/+bug/1179615
2014-01-21
Published