Moderate severityNVD Advisory· Published Mar 22, 2013· Updated Jun 16, 2026
CVE-2013-1865
CVE-2013-1865
Description
OpenStack Keystone Folsom (2012.2) does not properly perform revocation checks for Keystone PKI tokens when done through a server, which allows remote attackers to bypass intended access restrictions via a revoked PKI token.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
keystonePyPI | >= 2012.2, < 2012.2.4 | 2012.2.4 |
Affected products
3- cpe:2.3:o:canonical:ubuntu_linux:12.10:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
21- secunia.com/advisories/52657nvdVendor Advisory
- github.com/advisories/GHSA-22q6-wwq7-2jj9ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2013-1865ghsaADVISORY
- github.com/openstack/keystone/commit/255b1d43500f5d98ec73a0056525b492b14fec05ghsaWEB
- lists.fedoraproject.org/pipermail/package-announce/2013-April/101719.htmlnvdWEB
- lists.opensuse.org/opensuse-updates/2013-04/msg00000.htmlnvdWEB
- rhn.redhat.com/errata/RHSA-2013-0708.htmlnvdWEB
- www.openwall.com/lists/oss-security/2013/03/20/13nvdWEB
- www.ubuntu.com/usn/USN-1772-1nvdWEB
- access.redhat.com/errata/RHSA-2013:0708ghsaWEB
- access.redhat.com/security/cve/CVE-2013-1865ghsaWEB
- bugs.launchpad.net/keystone/+bug/1129713nvdWEB
- bugzilla.redhat.com/show_bug.cgighsaWEB
- github.com/pypa/advisory-database/tree/main/vulns/keystone/PYSEC-2013-39.yamlghsaWEB
- opendev.org/openstack/keystoneghsaPACKAGE
- review.openstack.orgghsaWEB
- review.openstack.org/24906ghsaWEB
- web.archive.org/web/20170715155558/http://www.securityfocus.com/bid/58616ghsaWEB
- osvdb.org/91532nvd
- www.securityfocus.com/bid/58616nvd
- review.openstack.orgnvd
News mentions
0No linked articles in our index yet.