python-keystoneclient
PyPI9 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting python-keystoneclientpage 1 of 1
- CVE-2013-2013LOWCVSS v2 2.1EG 2.1✓ Fixed in 0.2.42013-10-01
vulnerable: 0.1.1 ... 0.2.3 (7 versions)
The user-password-update command in python-keystoneclient before 0.2.4 accepts the new password in the --password argument, which allows local users to obtain sensitive information by listing the process.
- CVE-2013-2030LOWCVSS v2 2.1EG 2.1✓ Fixed in 0.2.42013-12-27
vulnerable: 0.1.1 ... 0.2.3 (7 versions)
keystone/middleware/auth_token.py in OpenStack Nova Folsom, Grizzly, and Havana uses an insecure temporary directory for storing signing certificates, which allows local users to spoof servers by pre-creating this directory, which is reuse…
- CVE-2013-2104MEDIUMCVSS v2 5.5EG 5.5✓ Fixed in 0.2.42014-01-21
vulnerable: 0.1.1 ... 0.2.3 (7 versions)
python-keystoneclient before 0.2.4, as used in OpenStack Keystone (Folsom), does not properly check expiry for PKI tokens, which allows remote authenticated users to (1) retain use of a token after it has expired, or (2) use a revoked toke…
- CVE-2013-2166CRITICALCVSS 9.8EG 9.8✓ Fixed in 0.3.02019-12-10
vulnerable: 0.2.3, 0.2.4, 0.2.5
python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache encryption bypass
- CVE-2013-2167CRITICALCVSS 9.8EG 9.8✓ Fixed in 0.3.02019-12-10
vulnerable: 0.2.3, 0.2.4, 0.2.5
python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache signing bypass
- CVE-2013-2255MEDIUMCVSS 5.9EG 5.9✓ Fixed in 0.4.02019-11-01
vulnerable: 0.1.1 ... 0.3.2 (12 versions)
HTTPSConnections in OpenStack Keystone 2013, OpenStack Compute 2013.1, and possibly other OpenStack components, fail to validate server-side SSL certificates.
- CVE-2014-0105MEDIUMCVSS v2 6.0EG 6.0✓ Fixed in 0.7.02014-04-15
vulnerable: 0.1.1 ... 0.6.0 (18 versions)
The auth_token middleware in the OpenStack Python client library for Keystone (aka python-keystoneclient) before 0.7.0 does not properly retrieve user tokens from memcache, which allows remote authenticated users to gain privileges in oppo…
- CVE-2014-7144MEDIUMCVSS v2 4.3EG 4.3✓ Fixed in 1.2.02014-10-02
vulnerable: 0.1.1 ... 1.1.1 (27 versions)
OpenStack keystonemiddleware (formerly python-keystoneclient) 0.x before 0.11.0 and 1.x before 1.2.0 disables certification verification when the "insecure" option is set in a paste configuration (paste.ini) file regardless of the value, w…
- CVE-2015-1852MEDIUMCVSS v2 4.3EG 4.3✓ Fixed in 1.4.02015-04-17
vulnerable: 0.1.1 ... 1.3.4 (36 versions)
The s3_token middleware in OpenStack keystonemiddleware before 1.6.0 and python-keystoneclient before 1.4.0 disables certification verification when the "insecure" option is set in a paste configuration (paste.ini) file regardless of the v…
Check whether python-keystoneclient is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for python-keystoneclient CVEs against the assets you own.
Start Free Scan →