CVE Vulnerabilities

CVE-2013-2059

Improper Authentication

Published: May 21, 2013 | Modified: Aug 29, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6 MEDIUM
AV:N/AC:M/Au:S/C:P/I:P/A:P
RedHat/V2
4 MODERATE
AV:N/AC:L/Au:S/C:N/I:P/A:N
RedHat/V3
Ubuntu
LOW

OpenStack Identity (Keystone) Folsom 2012.2.4 and earlier, Grizzly before 2013.1.1, and Havana does not immediately revoke the authentication token when deleting a user through the Keystone v2 API, which allows remote authenticated users to retain access via the token.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Keystone Openstack 2012.1 (including) 2012.1 (including)
Keystone Openstack 2013.1 (including) 2013.1 (including)
Keystone Ubuntu devel *
Keystone Ubuntu oneiric *
Keystone Ubuntu precise *
Keystone Ubuntu quantal *
Keystone Ubuntu raring *
Keystone Ubuntu upstream *

Potential Mitigations

References