Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2013-2104

Опубликовано: 21 янв. 2014
Источник: nvd
CVSS2: 5.5
EPSS Низкий

Описание

python-keystoneclient before 0.2.4, as used in OpenStack Keystone (Folsom), does not properly check expiry for PKI tokens, which allows remote authenticated users to (1) retain use of a token after it has expired, or (2) use a revoked token once it expires.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:openstack:python-keystoneclient:*:*:*:*:*:*:*:*
Версия до 0.2.3 (включая)
cpe:2.3:a:openstack:python-keystoneclient:0.2.2:*:*:*:*:*:*:*

EPSS

Процентиль: 73%
0.00769
Низкий

5.5 Medium

CVSS2

Дефекты

CWE-264

Связанные уязвимости

ubuntu
около 12 лет назад

python-keystoneclient before 0.2.4, as used in OpenStack Keystone (Folsom), does not properly check expiry for PKI tokens, which allows remote authenticated users to (1) retain use of a token after it has expired, or (2) use a revoked token once it expires.

redhat
больше 12 лет назад

python-keystoneclient before 0.2.4, as used in OpenStack Keystone (Folsom), does not properly check expiry for PKI tokens, which allows remote authenticated users to (1) retain use of a token after it has expired, or (2) use a revoked token once it expires.

debian
около 12 лет назад

python-keystoneclient before 0.2.4, as used in OpenStack Keystone (Fol ...

CVSS3: 7.5
github
больше 3 лет назад

python-keystoneclient missing expiration check in PKI token validation

EPSS

Процентиль: 73%
0.00769
Низкий

5.5 Medium

CVSS2

Дефекты

CWE-264