| Vulnerability Name: | CVE-2013-2059 (CCN-84135) | ||||||||||||||||
| Assigned: | 2013-05-09 | ||||||||||||||||
| Published: | 2013-05-09 | ||||||||||||||||
| Updated: | 2017-08-29 | ||||||||||||||||
| Summary: | OpenStack Identity (Keystone) Folsom 2012.2.4 and earlier, Grizzly before 2013.1.1, and Havana does not immediately revoke the authentication token when deleting a user through the Keystone v2 API, which allows remote authenticated users to retain access via the token. | ||||||||||||||||
| CVSS v3 Severity: | 3.5 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N)
| ||||||||||||||||
| CVSS v2 Severity: | 6.0 Medium (CVSS v2 Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P) 4.4 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P/E:U/RL:OF/RC:C)
3.0 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:N/I:P/A:N/E:U/RL:OF/RC:C)
| ||||||||||||||||
| Vulnerability Type: | CWE-287 | ||||||||||||||||
| Vulnerability Consequences: | Bypass Security | ||||||||||||||||
| References: | Source: MITRE Type: CNA CVE-2013-2059 Source: CCN Type: OpenStack Keystone Web site Welcome to Keystone, the OpenStack Identity Service! Source: FEDORA Type: UNKNOWN FEDORA-2013-8048 Source: FEDORA Type: UNKNOWN FEDORA-2013-8023 Source: SUSE Type: UNKNOWN openSUSE-SU-2013:0949 Source: CCN Type: OSSA 2013-011 Keystone tokens not immediately invalidated when user is deleted Source: OSVDB Type: UNKNOWN 93134 Source: CCN Type: SA53326 OpenStack Keystone Authentication Tokens Invalidation Security Issue Source: SECUNIA Type: Vendor Advisory 53326 Source: CCN Type: SA53339 OpenStack Keystone Authentication Tokens Invalidation Security Issue Source: SECUNIA Type: Vendor Advisory 53339 Source: MLIST Type: UNKNOWN [oss-security] 20130509 [OSSA 2013-011] Keystone tokens not immediately invalidated when user is deleted (CVE-2013-2059) Source: MLIST Type: UNKNOWN [oss-security] 20130509 RE: [Openstack] [OSSA 2013-011] Keystone tokens not immediately invalidated when user is deleted (CVE-2013-2059) Source: BID Type: UNKNOWN 59787 Source: CCN Type: BID-59787 OpenStack Keystone Tokens Validation Security Bypass Vulnerability Source: CONFIRM Type: Exploit https://bugs.launchpad.net/keystone/+bug/1166670 Source: XF Type: UNKNOWN keystone-cve20132059-security-bypass(84135) Source: XF Type: UNKNOWN keystone-cve20132059-security-bypass(84135) Source: CCN Type: WhiteSource Vulnerability Database CVE-2013-2059 | ||||||||||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||
| Oval Definitions | |||||||||||||||||
| |||||||||||||||||
| BACK | |||||||||||||||||