CVE-2013-2013

python-keystoneclient < 0.2.4 - Exposure of Sensitive Information via Command Line Argument

Title source: llm
STIX 2.1

Description

The user-password-update command in python-keystoneclient before 0.2.4 accepts the new password in the --password argument, which allows local users to obtain sensitive information by listing the process.

References (3)

Core 3
Core References
Patch mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2013/05/23/4
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16937

Scores

EPSS 0.0006
EPSS Percentile 20.1%

Details

CWE
CWE-200
Status published
Products (3)
openstack/python-keystoneclient 0.2.2
openstack/python-keystoneclient < 0.2.3
pypi/python-keystoneclient 0 - 0.2.4PyPI
Published Oct 01, 2013
Tracked Since Feb 18, 2026