VYPR
High severityNVD Advisory· Published Jan 21, 2014· Updated Apr 29, 2026

CVE-2013-2104

CVE-2013-2104

Description

python-keystoneclient before 0.2.4, as used in OpenStack Keystone (Folsom), does not properly check expiry for PKI tokens, which allows remote authenticated users to (1) retain use of a token after it has expired, or (2) use a revoked token once it expires.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
python-keystoneclientPyPI
< 0.2.40.2.4

Affected products

2
  • cpe:2.3:a:openstack:python-keystoneclient:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:openstack:python-keystoneclient:*:*:*:*:*:*:*:*range: <=0.2.3
    • cpe:2.3:a:openstack:python-keystoneclient:0.2.2:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

12

News mentions

0

No linked articles in our index yet.