CVE Vulnerabilities

CVE-2013-4222

Insufficiently Protected Credentials

Published: Sep 30, 2013 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
4 MODERATE
AV:N/AC:L/Au:S/C:N/I:P/A:N
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

OpenStack Identity (Keystone) Folsom, Grizzly 2013.1.3 and earlier, and Havana before havana-3 does not properly revoke user tokens when a tenant is disabled, which allows remote authenticated users to retain access via the token.

Weakness

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Affected Software

NameVendorStart VersionEnd Version
KeystoneOpenstack2013.1 (including)2013.1.3 (including)
OpenStack 3 for RHEL 6RedHatopenstack-keystone-0:2013.1.4-1.el6ost*
KeystoneUbuntuquantal*
KeystoneUbunturaring*
KeystoneUbuntuupstream*

Potential Mitigations

References