Lucene search

K
ubuntucveUbuntu.comUB:CVE-2013-2059
HistoryMay 09, 2013 - 12:00 a.m.

CVE-2013-2059

2013-05-0900:00:00
ubuntu.com
ubuntu.com
11

CVSS2

6

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:S/C:P/I:P/A:P

EPSS

0.013

Percentile

86.1%

OpenStack Identity (Keystone) Folsom 2012.2.4 and earlier, Grizzly before
2013.1.1, and Havana does not immediately revoke the authentication token
when deleting a user through the Keystone v2 API, which allows remote
authenticated users to retain access via the token.

Bugs

Notes

Author Note
jdstrand upstream states Essex is affected
OSVersionArchitecturePackageVersionFilename
ubuntu12.04noarchkeystone< 2012.1.3+stable-20130423-f48dd0fc-0ubuntu1.1UNKNOWN
ubuntu12.10noarchkeystone< 2012.2.3+stable-20130206-82c87e56-0ubuntu2.1UNKNOWN
ubuntu13.04noarchkeystone< 1:2013.1-0ubuntu1.1UNKNOWN

CVSS2

6

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:S/C:P/I:P/A:P

EPSS

0.013

Percentile

86.1%