Moderate severityNVD Advisory· Published Sep 23, 2013· Updated Jun 16, 2026
CVE-2013-4294
CVE-2013-4294
Description
The (1) mamcache and (2) KVS token backends in OpenStack Identity (Keystone) Folsom 2012.2.x and Grizzly before 2013.1.4 do not properly compare the PKI token revocation list with PKI tokens, which allow remote attackers to bypass intended access restrictions via a revoked PKI token.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
keystonePyPI | >= 2012.2.0, < 2013.1.4 | 2013.1.4 |
Affected products
10cpe:2.3:a:openstack:keystone:2012.2:*:*:*:*:*:*:*+ 8 more
- cpe:2.3:a:openstack:keystone:2012.2:*:*:*:*:*:*:*
- cpe:2.3:a:openstack:keystone:2012.2.1:*:*:*:*:*:*:*
- cpe:2.3:a:openstack:keystone:2012.2.2:*:*:*:*:*:*:*
- cpe:2.3:a:openstack:keystone:2012.2.3:*:*:*:*:*:*:*
- cpe:2.3:a:openstack:keystone:2012.2.4:*:*:*:*:*:*:*
- cpe:2.3:a:openstack:keystone:2013.1:*:*:*:*:*:*:*
- cpe:2.3:a:openstack:keystone:2013.1.1:*:*:*:*:*:*:*
- cpe:2.3:a:openstack:keystone:2013.1.2:*:*:*:*:*:*:*
- cpe:2.3:a:openstack:keystone:2013.1.3:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
13- seclists.org/oss-sec/2013/q3/586nvdPatchWEB
- bugs.launchpad.net/keystone/+bug/1202952nvdVendor AdvisoryWEB
- github.com/advisories/GHSA-5qpp-v56f-mqfmghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2013-4294ghsaADVISORY
- rhn.redhat.com/errata/RHSA-2013-1285.htmlnvdWEB
- www.ubuntu.com/usn/USN-2002-1nvdWEB
- access.redhat.com/errata/RHSA-2013:1285ghsaWEB
- access.redhat.com/security/cve/CVE-2013-4294ghsaWEB
- bugzilla.redhat.com/show_bug.cgighsaWEB
- github.com/pypa/advisory-database/tree/main/vulns/keystone/PYSEC-2013-42.yamlghsaWEB
- opendev.org/openstack/keystoneghsaPACKAGE
- osvdb.org/97237nvd
- secunia.com/advisories/54706nvd
News mentions
0No linked articles in our index yet.