Moderate severityNVD Advisory· Published Sep 23, 2013· Updated Apr 29, 2026
CVE-2013-4294
CVE-2013-4294
Description
The (1) mamcache and (2) KVS token backends in OpenStack Identity (Keystone) Folsom 2012.2.x and Grizzly before 2013.1.4 do not properly compare the PKI token revocation list with PKI tokens, which allow remote attackers to bypass intended access restrictions via a revoked PKI token.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
keystonePyPI | >= 2012.2.0, < 2013.1.4 | 2013.1.4 |
Affected products
9cpe:2.3:a:openstack:keystone:2012.2:*:*:*:*:*:*:*+ 8 more
- cpe:2.3:a:openstack:keystone:2012.2:*:*:*:*:*:*:*
- cpe:2.3:a:openstack:keystone:2012.2.1:*:*:*:*:*:*:*
- cpe:2.3:a:openstack:keystone:2012.2.2:*:*:*:*:*:*:*
- cpe:2.3:a:openstack:keystone:2012.2.3:*:*:*:*:*:*:*
- cpe:2.3:a:openstack:keystone:2012.2.4:*:*:*:*:*:*:*
- cpe:2.3:a:openstack:keystone:2013.1:*:*:*:*:*:*:*
- cpe:2.3:a:openstack:keystone:2013.1.1:*:*:*:*:*:*:*
- cpe:2.3:a:openstack:keystone:2013.1.2:*:*:*:*:*:*:*
- cpe:2.3:a:openstack:keystone:2013.1.3:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
13- seclists.org/oss-sec/2013/q3/586nvdPatchWEB
- bugs.launchpad.net/keystone/+bug/1202952nvdVendor AdvisoryWEB
- github.com/advisories/GHSA-5qpp-v56f-mqfmghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2013-4294ghsaADVISORY
- rhn.redhat.com/errata/RHSA-2013-1285.htmlnvdWEB
- www.ubuntu.com/usn/USN-2002-1nvdWEB
- access.redhat.com/errata/RHSA-2013:1285ghsaWEB
- access.redhat.com/security/cve/CVE-2013-4294ghsaWEB
- bugzilla.redhat.com/show_bug.cgighsaWEB
- github.com/pypa/advisory-database/tree/main/vulns/keystone/PYSEC-2013-42.yamlghsaWEB
- opendev.org/openstack/keystoneghsaPACKAGE
- osvdb.org/97237nvd
- secunia.com/advisories/54706nvd
News mentions
0No linked articles in our index yet.