CVE-2013-2167

CRITICAL

Openstack Python-keystoneclient < 0.2.5 - Data Authenticity Bypass

Title source: rule

Description

python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache signing bypass

Scores

CVSS v3 9.8
EPSS 0.0083
EPSS Percentile 74.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-345
Status published

Affected Products (6)

openstack/python-keystoneclient < 0.2.5
redhat/openstack
debian/debian_linux
debian/debian_linux
debian/debian_linux
pypi/python-keystoneclient < 0.3.0PyPI

Timeline

Published Dec 10, 2019
Tracked Since Feb 18, 2026