CVE-2013-4222

Openstack Keystone < 2013.1.3 - Insufficiently Protected Credentials

Title source: rule

Description

OpenStack Identity (Keystone) Folsom, Grizzly 2013.1.3 and earlier, and Havana before havana-3 does not properly revoke user tokens when a tenant is disabled, which allows remote authenticated users to retain access via the token.

Scores

EPSS 0.0058
EPSS Percentile 68.5%

Classification

CWE
CWE-522
Status draft

Affected Products (5)

openstack/keystone < 2013.1.3
fedoraproject/fedora
canonical/ubuntu_linux
canonical/ubuntu_linux
redhat/openstack

Timeline

Published Sep 30, 2013
Tracked Since Feb 18, 2026