python-keystoneclient
PyPI9 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting python-keystoneclientpage 1 of 1
- CVE-2013-2013NONECVSS 0.0EG 0.0✓ Fixed in 0.2.42013-10-01
vulnerable: 0.1.1 ... 0.2.3 (7 versions)
The user-password-update command in python-keystoneclient before 0.2.4 accepts the new password in the --password argument, which allows local users to obtain sensitive information by listing the process.
- CVE-2013-2030NONECVSS 0.0EG 0.0✓ Fixed in 0.2.42013-12-27
vulnerable: 0.1.1 ... 0.2.3 (7 versions)
keystone/middleware/auth_token.py in OpenStack Nova Folsom, Grizzly, and Havana uses an insecure temporary directory for storing signing certificates, which allows local users to spoof servers by pre-creating this directory, which is reuse…
- CVE-2013-2104NONECVSS 0.0EG 0.0✓ Fixed in 0.2.42014-01-21
vulnerable: 0.1.1 ... 0.2.3 (7 versions)
python-keystoneclient before 0.2.4, as used in OpenStack Keystone (Folsom), does not properly check expiry for PKI tokens, which allows remote authenticated users to (1) retain use of a token after it has expired, or (2) use a revoked toke…
- CVE-2013-2166CRITICALCVSS 9.8EG 9.8✓ Fixed in 0.3.02019-12-10
vulnerable: 0.2.3, 0.2.4, 0.2.5
python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache encryption bypass
- CVE-2013-2167CRITICALCVSS 9.8EG 9.8✓ Fixed in 0.3.02019-12-10
vulnerable: 0.2.3, 0.2.4, 0.2.5
python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache signing bypass
- CVE-2013-2255MEDIUMCVSS 5.9EG 5.9✓ Fixed in 0.4.02019-11-01
vulnerable: 0.1.1 ... 0.3.2 (12 versions)
HTTPSConnections in OpenStack Keystone 2013, OpenStack Compute 2013.1, and possibly other OpenStack components, fail to validate server-side SSL certificates.
- CVE-2014-0105NONECVSS 0.0EG 0.0✓ Fixed in 0.7.02014-04-15
vulnerable: 0.1.1 ... 0.6.0 (18 versions)
The auth_token middleware in the OpenStack Python client library for Keystone (aka python-keystoneclient) before 0.7.0 does not properly retrieve user tokens from memcache, which allows remote authenticated users to gain privileges in oppo…
- CVE-2014-7144NONECVSS 0.0EG 0.0✓ Fixed in 1.2.02014-10-02
vulnerable: 0.1.1 ... 1.1.1 (27 versions)
OpenStack keystonemiddleware (formerly python-keystoneclient) 0.x before 0.11.0 and 1.x before 1.2.0 disables certification verification when the "insecure" option is set in a paste configuration (paste.ini) file regardless of the value, w…
- CVE-2015-1852NONECVSS 0.0EG 0.0✓ Fixed in 1.4.02015-04-17
vulnerable: 0.1.1 ... 1.3.4 (36 versions)
The s3_token middleware in OpenStack keystonemiddleware before 1.6.0 and python-keystoneclient before 1.4.0 disables certification verification when the "insecure" option is set in a paste configuration (paste.ini) file regardless of the v…
Check whether python-keystoneclient is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for python-keystoneclient CVEs against the assets you own.
Start Free Scan →