PT-2014-2551 · Openstack · Python-Keystoneclient
Alex Meade
+2
·
Published
2014-01-21
·
Updated
2023-02-13
·
CVE-2013-2104
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
python-keystoneclient versions prior to 0.2.4
Description
The issue allows remote authenticated users to retain use of a token after it has expired or use a revoked token once it expires, due to improper checking of expiry for PKI tokens.
Recommendations
For python-keystoneclient versions prior to 0.2.4, update to version 0.2.4 or later to resolve the issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Python-Keystoneclient