CVE-2013-2013
python-keystoneclient < 0.2.4 - Exposure of Sensitive Information via Command Line Argument
Title source: llmDescription
The user-password-update command in python-keystoneclient before 0.2.4 accepts the new password in the --password argument, which allows local users to obtain sensitive information by listing the process.
References (3)
Core 3
Core References
Patch mailing-list
x_refsource_mlist
http://www.openwall.com/lists/oss-security/2013/05/23/4
Third Party Advisory, VDB Entry vdb-entry
signature
x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16937
Issue Tracking x_refsource_confirm
https://bugs.launchpad.net/python-keystoneclient/+bug/938315
Scores
EPSS
0.0006
EPSS Percentile
20.1%
Details
CWE
CWE-200
Status
published
Products (3)
openstack/python-keystoneclient
0.2.2
openstack/python-keystoneclient
< 0.2.3
pypi/python-keystoneclient
0 - 0.2.4PyPI
Published
Oct 01, 2013
Tracked Since
Feb 18, 2026