Unrated severityNVD Advisory· Published Sep 30, 2013· Updated Apr 29, 2026
CVE-2013-4222
CVE-2013-4222
Description
OpenStack Identity (Keystone) Folsom, Grizzly 2013.1.3 and earlier, and Havana before havana-3 does not properly revoke user tokens when a tenant is disabled, which allows remote authenticated users to retain access via the token.
Affected products
5- cpe:2.3:o:fedoraproject:fedora:20:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:12.10:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:canonical:ubuntu_linux:12.10:*:*:*:*:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:13.04:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- lists.fedoraproject.org/pipermail/package-announce/2013-September/116489.htmlnvdThird Party Advisory
- rhn.redhat.com/errata/RHSA-2013-1524.htmlnvdThird Party Advisory
- www.ubuntu.com/usn/USN-2002-1nvdThird Party Advisory
- bugs.launchpad.net/ossn/+bug/1179955nvdIssue TrackingThird Party Advisory
News mentions
0No linked articles in our index yet.