Moderate severityNVD Advisory· Published Dec 27, 2013· Updated Jun 16, 2026
CVE-2013-2030
CVE-2013-2030
Description
keystone/middleware/auth_token.py in OpenStack Nova Folsom, Grizzly, and Havana uses an insecure temporary directory for storing signing certificates, which allows local users to spoof servers by pre-creating this directory, which is reused by Nova, as demonstrated using /tmp/keystone-signing-nova on Fedora.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
python-keystoneclientPyPI | < 0.2.4 | 0.2.4 |
Affected products
10Patches
Vulnerability mechanics
References
12- lists.openstack.org/pipermail/openstack-announce/2013-May/000098.htmlnvdPatchVendor AdvisoryWEB
- github.com/advisories/GHSA-pxxv-rv32-2qgvghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2013-2030ghsaADVISORY
- lists.fedoraproject.org/pipermail/package-announce/2013-May/105916.htmlnvdWEB
- www.openwall.com/lists/oss-security/2013/05/09/2nvdWEB
- bugs.launchpad.net/nova/+bug/1174608nvdWEB
- bugzilla.redhat.com/show_bug.cginvdWEB
- github.com/openstack/nova/commit/58d6879b1caaa750c39c8e452a0634c24ffef2ceghsaWEB
- github.com/openstack/nova/commit/74aa04e2ca7942cb1e1a86dcbaffeb72d260ccd7ghsaWEB
- github.com/openstack/nova/commit/7bf3e8d3e254d817ff5ae7ef1f2884b10410ca60ghsaWEB
- github.com/openstack/python-keystoneclient/commit/1736e2ffb12f70eeebed019448bc14def48aa036ghsaWEB
- github.com/pypa/advisory-database/tree/main/vulns/nova/PYSEC-2013-45.yamlghsaWEB
News mentions
0No linked articles in our index yet.