CVE-2013-2166
published 2019-12-10CVE-2013-2166: python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache encryption bypass
PriorityP346critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.76%
75.5th percentile
python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache encryption bypass
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | python-keystoneclient | < python-keystoneclient 1:0.2.5-2 (bookworm) | python-keystoneclient 1:0.2.5-2 (bookworm) |
| fedoraproject | fedora | — | — |
| openstack | python-keystoneclient | 0.2.3 – 0.2.5 | — |
| python-keystoneclient | python-keystoneclient | < 0.2.6 | 0.2.6 |
| python-keystoneclient | python-keystoneclient | >= 0 < 1:0.2.5-2 | 1:0.2.5-2 |
| python-keystoneclient | python-keystoneclient | >= 0 < 1:0.2.5-2 | 1:0.2.5-2 |
| python-keystoneclient | python-keystoneclient | >= 0 < 1:0.2.5-2 | 1:0.2.5-2 |
| python-keystoneclient | python-keystoneclient | >= 0 < 1:0.2.5-2 | 1:0.2.5-2 |
| python-keystoneclient | python-keystoneclient | >= 0.2.3 < 0.3.0 | 0.3.0 |
| redhat | openstack | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Inadequate Encryption Strength in python-keystoneclient
osv·2021-10-12
CVE-2013-2166 [CRITICAL] Inadequate Encryption Strength in python-keystoneclient
Inadequate Encryption Strength in python-keystoneclient
python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache encryption bypass.
GHSA
Inadequate Encryption Strength in python-keystoneclient
ghsa·2021-10-12
CVE-2013-2166 [CRITICAL] CWE-326 Inadequate Encryption Strength in python-keystoneclient
Inadequate Encryption Strength in python-keystoneclient
python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache encryption bypass.
OSV
CVE-2013-2166: python-keystoneclient version 0
osv·2019-12-10·CVSS 9.8
CVE-2013-2166 [CRITICAL] CVE-2013-2166: python-keystoneclient version 0
python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache encryption bypass
Red Hat
python-keystoneclient: middleware memcache encryption and signing bypass
vendor_redhat·2013-06-19·CVSS 9.8
CVE-2013-2166 [CRITICAL] CWE-345 python-keystoneclient: middleware memcache encryption and signing bypass
python-keystoneclient: middleware memcache encryption and signing bypass
python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache encryption bypass
Debian
CVE-2013-2166: python-keystoneclient - python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache encryption ...
vendor_debian·2013·CVSS 9.8
CVE-2013-2166 [CRITICAL] CVE-2013-2166: python-keystoneclient - python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache encryption ...
python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache encryption bypass
Scope: local
bookworm: resolved (fixed in 1:0.2.5-2)
bullseye: resolved (fixed in 1:0.2.5-2)
forky: resolved (fixed in 1:0.2.5-2)
sid: resolved (fixed in 1:0.2.5-2)
trixie: resolved (fixed in 1:0.2.5-2)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-2166 CVE-2013-2167 python-keystoneclient: middleware memcache encryption and signing bypass [fedora-all]
bugzilla·2013-06-19·CVSS 9.8
CVE-2013-2166 [CRITICAL] CVE-2013-2166 CVE-2013-2167 python-keystoneclient: middleware memcache encryption and signing bypass [fedora-all]
CVE-2013-2166 CVE-2013-2167 python-keystoneclient: middleware memcache encryption and signing bypass [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when ava
Bugzilla
CVE-2013-2166 CVE-2013-2167 python-keystoneclient: middleware memcache encryption and signing bypass [epel-6]
bugzilla·2013-06-19·CVSS 9.8
CVE-2013-2166 [CRITICAL] CVE-2013-2166 CVE-2013-2167 python-keystoneclient: middleware memcache encryption and signing bypass [epel-6]
CVE-2013-2166 CVE-2013-2167 python-keystoneclient: middleware memcache encryption and signing bypass [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when av
Bugzilla
CVE-2013-2166 CVE-2013-2167 python-keystoneclient: middleware memcache encryption and signing bypass
bugzilla·2013-06-13·CVSS 9.8
CVE-2013-2166 [CRITICAL] CVE-2013-2166 CVE-2013-2167 python-keystoneclient: middleware memcache encryption and signing bypass
CVE-2013-2166 CVE-2013-2167 python-keystoneclient: middleware memcache encryption and signing bypass
Thierry Carrez ([email protected]) reports:
Title: Issues in Keystone middleware memcache signing/encryption feature
Reporter: Paul McMillan (Nebula)
Products: python-keystoneclient
Affects: version 0.2.3 to 0.2.5
Description:
Paul McMillan from Nebula reported multiple issues in the implementation
of memcache signing/encryption feature in Keystone client middleware. An
attacker with direct write access to the memcache backend (or in a
man-in-the-middle position) could insert malicious data and potentially
bypass the encryption (CVE-2013-2166) or signing (CVE-2013-2167)
security strategy that was specified. Only setups that make use of
memcache caching in the Keystone middleware (speci
http://lists.fedoraproject.org/pipermail/package-announce/2013-August/113944.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0992.htmlhttp://www.openwall.com/lists/oss-security/2013/06/19/5http://www.securityfocus.com/bid/60684https://access.redhat.com/security/cve/cve-2013-2166https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-2166https://bugzilla.suse.com/show_bug.cgi?id=CVE-2013-2166https://security-tracker.debian.org/tracker/CVE-2013-2166http://lists.fedoraproject.org/pipermail/package-announce/2013-August/113944.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0992.htmlhttp://www.openwall.com/lists/oss-security/2013/06/19/5http://www.securityfocus.com/bid/60684https://access.redhat.com/security/cve/cve-2013-2166https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-2166https://bugzilla.suse.com/show_bug.cgi?id=CVE-2013-2166https://security-tracker.debian.org/tracker/CVE-2013-2166
2019-12-10
Published