Lucene search

K
nvd[email protected]NVD:CVE-2013-2059
HistoryMay 21, 2013 - 6:55 p.m.

CVE-2013-2059

2013-05-2118:55:02
CWE-287
web.nvd.nist.gov
7

CVSS2

6

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:S/C:P/I:P/A:P

AI Score

6.3

Confidence

Low

EPSS

0.013

Percentile

86.1%

OpenStack Identity (Keystone) Folsom 2012.2.4 and earlier, Grizzly before 2013.1.1, and Havana does not immediately revoke the authentication token when deleting a user through the Keystone v2 API, which allows remote authenticated users to retain access via the token.

Affected configurations

Nvd
Node
openstackkeystoneMatch2012.1
OR
openstackkeystoneMatch2013.1

CVSS2

6

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:S/C:P/I:P/A:P

AI Score

6.3

Confidence

Low

EPSS

0.013

Percentile

86.1%