6
CVSSv2

CVE-2013-2059

Published: 21/05/2013 Updated: 29/08/2017
CVSS v2 Base Score: 6 | Impact Score: 6.4 | Exploitability Score: 6.8
VMScore: 534
Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P

Vulnerability Summary

OpenStack Identity (Keystone) Folsom 2012.2.4 and previous versions, Grizzly prior to 2013.1.1, and Havana does not immediately revoke the authentication token when deleting a user through the Keystone v2 API, which allows remote authenticated users to retain access via the token.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

openstack keystone 2012.1

openstack keystone 2013.1

Vendor Advisories

Debian Bug report logs - #707598 CVE-2013-2059: Keystone tokens not immediately invalidated when user is deleted [OSSA 2013-011] Package: keystone; Maintainer for keystone is Debian OpenStack <team+openstack@trackerdebianorg>; Source for keystone is src:keystone (PTS, buildd, popcon) Reported by: Luciano Bello <luciano@ ...
Keystone would allow unintended access over the network ...
OpenStack Identity (Keystone) Folsom 201224 and earlier, Grizzly before 201311, and Havana does not immediately revoke the authentication token when deleting a user through the Keystone v2 API, which allows remote authenticated users to retain access via the token ...