CVE-2013-6391

Openstack Keystone < 2013.2.1 - Improper Privilege Management

Title source: rule

Description

The ec2tokens API in OpenStack Identity (Keystone) before Havana 2013.2.1 and Icehouse before icehouse-2 does not return a trust-scoped token when one is received, which allows remote trust users to gain privileges by generating EC2 credentials from a trust-scoped token and using them in an ec2tokens API request.

Scores

EPSS 0.0050
EPSS Percentile 65.5%

Classification

CWE
CWE-269
Status draft

Affected Products (3)

openstack/keystone < 2013.2.1
canonical/ubuntu_linux
redhat/openstack

Timeline

Published Dec 14, 2013
Tracked Since Feb 18, 2026