keystonemiddleware
PyPI3 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting keystonemiddlewarepage 1 of 1
- CVE-2014-7144NONECVSS 0.0EG 0.0✓ Fixed in 1.2.02014-10-02
vulnerable: 0, 1.0.0, 1.1.0, 1.1.1
OpenStack keystonemiddleware (formerly python-keystoneclient) 0.x before 0.11.0 and 1.x before 1.2.0 disables certification verification when the "insecure" option is set in a paste configuration (paste.ini) file regardless of the value, w…
- CVE-2015-1852NONECVSS 0.0EG 0.0✓ Fixed in 1.6.02015-04-17
vulnerable: 0 ... 1.5.3 (13 versions)
The s3_token middleware in OpenStack keystonemiddleware before 1.6.0 and python-keystoneclient before 1.4.0 disables certification verification when the "insecure" option is set in a paste configuration (paste.ini) file regardless of the v…
- CVE-2015-7546HIGHCVSS 7.5EG 7.5✓ Fixed in 2.3.32016-02-03
vulnerable: 0 ... 2.3.2 (21 versions)
The identity service in OpenStack Identity (Keystone) before 2015.1.3 (Kilo) and 8.0.x before 8.0.2 (Liberty) and keystonemiddleware (formerly python-keystoneclient) before 1.5.4 (Kilo) and Liberty before 2.3.3 does not properly invalidate…
Check whether keystonemiddleware is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for keystonemiddleware CVEs against the assets you own.
Start Free Scan →