Lucene search

K
nvd[email protected]NVD:CVE-2013-4222
HistorySep 30, 2013 - 10:55 p.m.

CVE-2013-4222

2013-09-3022:55:04
CWE-522
web.nvd.nist.gov
5

CVSS2

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

AI Score

6.1

Confidence

Low

EPSS

0.003

Percentile

68.5%

OpenStack Identity (Keystone) Folsom, Grizzly 2013.1.3 and earlier, and Havana before havana-3 does not properly revoke user tokens when a tenant is disabled, which allows remote authenticated users to retain access via the token.

Affected configurations

Nvd
Node
openstackkeystoneRange2013.12013.1.3
Node
fedoraprojectfedoraMatch20
Node
canonicalubuntu_linuxMatch12.10
OR
canonicalubuntu_linuxMatch13.04
Node
redhatopenstackMatch3.0

CVSS2

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

AI Score

6.1

Confidence

Low

EPSS

0.003

Percentile

68.5%