Vulnerability Name: | CVE-2013-2104 (CCN-84579) | ||||||||||||||||||||
Assigned: | 2013-05-28 | ||||||||||||||||||||
Published: | 2013-05-28 | ||||||||||||||||||||
Updated: | 2023-02-13 | ||||||||||||||||||||
Summary: | OpenStack Keystone could allow a remote attacker to bypass security restrictions, caused by an error within the Keystone authentication middleware when checking the expiration of PKI tokens. An attacker could exploit this vulnerability to bypass restrictions and treat an expired token as valid. | ||||||||||||||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||||||||||||||
CVSS v2 Severity: | 5.5 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:N/I:P/A:P) 4.0 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:N/I:P/A:P/E:U/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
| ||||||||||||||||||||
Vulnerability Consequences: | Bypass Security | ||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2013-2104 Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com Source: CCN Type: SA53550 OpenStack Keystone PKI Missed Expiration Check Security Bypass Security Issue Source: CCN Type: OSSA 2013-014 Missing expiration check in Keystone PKI tokens validation (CVE-2013-2104) Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com Source: CCN Type: BID-60193 OpenStack Keystone and python-keystoneclient PKI Tokens Validation Security Bypass Vulnerability Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com Source: XF Type: UNKNOWN keystone-cve20132104-sec-bypass(84579) | ||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||
| |||||||||||||||||||||
BACK |