Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2013-2013

Опубликовано: 01 окт. 2013
Источник: debian
EPSS Низкий

Описание

The user-password-update command in python-keystoneclient before 0.2.4 accepts the new password in the --password argument, which allows local users to obtain sensitive information by listing the process.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
python-keystoneclientfixed1:0.2.5-1package
python-keystoneclientfixed2012.1-3+deb7u1wheezypackage

Примечания

  • https://bugs.launchpad.net/python-keystoneclient/+bug/938315

  • https://review.openstack.org/28702

EPSS

Процентиль: 20%
0.00065
Низкий

Связанные уязвимости

ubuntu
больше 12 лет назад

The user-password-update command in python-keystoneclient before 0.2.4 accepts the new password in the --password argument, which allows local users to obtain sensitive information by listing the process.

redhat
почти 14 лет назад

The user-password-update command in python-keystoneclient before 0.2.4 accepts the new password in the --password argument, which allows local users to obtain sensitive information by listing the process.

nvd
больше 12 лет назад

The user-password-update command in python-keystoneclient before 0.2.4 accepts the new password in the --password argument, which allows local users to obtain sensitive information by listing the process.

CVSS3: 2.9
github
больше 3 лет назад

python-keystoneclient unsecure user password update

EPSS

Процентиль: 20%
0.00065
Низкий