{"id":"CVE-2013-1865","aliases":["PYSEC-2013-39"],"url":"https://o3.security/vulnerability/CVE-2013-1865","summary":"OpenStack Keystone Improper Authentication vulnerability","details":"OpenStack Keystone Folsom (2012.2) does not properly perform revocation checks for Keystone PKI tokens when done through a server, which allows remote attackers to bypass intended access restrictions via a revoked PKI token.","published":"2022-05-17T04:56:52Z","modified":"2024-11-26T18:38:40Z","cvss":{"score":5.3,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"keystone","fixedVersion":"2012.2.4"}],"fix":{"url":"http://github.com/openstack/keystone/commit/255b1d43500f5d98ec73a0056525b492b14fec05","label":"openstack/keystone@255b1d4"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2013-1865"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2013:0708"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2013-1865"},{"type":"WEB","url":"https://bugs.launchpad.net/keystone/+bug/1129713"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=922230"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/keystone/PYSEC-2013-39.yaml"},{"type":"PACKAGE","url":"https://opendev.org/openstack/keystone"},{"type":"WEB","url":"https://review.openstack.org/#/c/24906"},{"type":"WEB","url":"https://review.openstack.org/24906"},{"type":"WEB","url":"https://web.archive.org/web/20170715155558/http://www.securityfocus.com/bid/58616"},{"type":"WEB","url":"http://github.com/openstack/keystone/commit/255b1d43500f5d98ec73a0056525b492b14fec05"},{"type":"WEB","url":"http://lists.fedoraproject.org/pipermail/package-announce/2013-April/101719.html"},{"type":"WEB","url":"http://lists.opensuse.org/opensuse-updates/2013-04/msg00000.html"},{"type":"WEB","url":"http://rhn.redhat.com/errata/RHSA-2013-0708.html"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2013/03/20/13"},{"type":"WEB","url":"http://www.ubuntu.com/usn/USN-1772-1"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-11-26T18:38:40Z"}}