CVE-2013-4294

medium
Published 2022-05-17 · Modified 2024-11-25
CVSS v3
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS v2
5.0
VIR risk
5.0

Description

The (1) mamcache and (2) KVS token backends in OpenStack Identity (Keystone) Folsom 2012.2.x and Grizzly before 2013.1.4 do not properly compare the PKI token revocation list with PKI tokens, which allow remote attackers to bypass intended access restrictions via a revoked PKI token.

Predictions

Exploit likelihood
30%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2013-4294

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — https://bugs.launchpad.net/keystone/+bug/1202952

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://seclists.org/oss-sec/2013/q3/586

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed2013.1.3-2
debian debianbullseyefixed2013.1.3-2
debian debianforkyfixed2013.1.3-2
debian debiansidfixed2013.1.3-2
debian debiantrixiefixed2013.1.3-2

Package impact

EcosystemPackageVulnerableFixed
python PyPIkeystone>=2012.2.0,<2013.1.42013.1.4

Application impact

VendorProductVersionsFixed
openstackkeystone2012.2
openstackkeystone2012.2.1
openstackkeystone2012.2.2
openstackkeystone2012.2.3
openstackkeystone2012.2.4
openstackkeystone2013.1
openstackkeystone2013.1.1
openstackkeystone2013.1.2
openstackkeystone2013.1.3

References

CWEs

CWE-264

Verify integrity in audit chain (admin only). AS-IS.