CVE-2013-2059

Openstack Keystone < 8.0.0a0 - Authentication Bypass

Title source: rule

Description

OpenStack Identity (Keystone) Folsom 2012.2.4 and earlier, Grizzly before 2013.1.1, and Havana does not immediately revoke the authentication token when deleting a user through the Keystone v2 API, which allows remote authenticated users to retain access via the token.

Scores

EPSS 0.0091
EPSS Percentile 75.5%

Classification

CWE
CWE-287
Status draft

Affected Products (3)

openstack/keystone
openstack/keystone
pypi/keystone < 8.0.0a0PyPI

Timeline

Published May 21, 2013
Tracked Since Feb 18, 2026