5.5
CVSSv2

CVE-2013-2104

Published: 21/01/2014 Updated: 13/02/2023
CVSS v2 Base Score: 5.5 | Impact Score: 4.9 | Exploitability Score: 8
VMScore: 490
Vector: AV:N/AC:L/Au:S/C:N/I:P/A:P

Vulnerability Summary

python-keystoneclient prior to 0.2.4, as used in OpenStack Keystone (Folsom), does not properly check expiry for PKI tokens, which allows remote authenticated users to (1) retain use of a token after it has expired, or (2) use a revoked token once it expires.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

openstack python-keystoneclient 0.2.2

openstack python-keystoneclient

Vendor Advisories

The python client library for Keystone did not properly verify expired PKI tokens ...
Keystone did not always properly verify expired PKI tokens or properly authenticate users ...
python-keystoneclient before 024, as used in OpenStack Keystone (Folsom), does not properly check expiry for PKI tokens, which allows remote authenticated users to (1) retain use of a token after it has expired, or (2) use a revoked token once it expires ...