Lucene search

K
ubuntuUbuntuUSN-1851-1
HistoryJun 03, 2013 - 12:00 a.m.

python-keystoneclient vulnerability

2013-06-0300:00:00
ubuntu.com
36

CVSS2

5.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:N/I:P/A:P

AI Score

9.4

Confidence

High

EPSS

0.002

Percentile

64.8%

Releases

  • Ubuntu 13.04

Packages

  • python-keystoneclient - Client library for OpenStack Identity API

Details

Eoghan Glynn and Alex Meade discovered that python-keystoneclient did not
properly perform expiry checks for the PKI tokens used in Keystone. If
Keystone were setup to use PKI tokens (the default in Ubuntu 13.04), a
previously authenticated user could continue to use a PKI token for longer
than intended.

OSVersionArchitecturePackageVersionFilename
Ubuntu13.04noarchpython-keystoneclient< 1:0.2.3-0ubuntu2.2UNKNOWN

CVSS2

5.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:N/I:P/A:P

AI Score

9.4

Confidence

High

EPSS

0.002

Percentile

64.8%