High severityNVD Advisory· Published Apr 1, 2014· Updated Jun 17, 2026
CVE-2014-2237
CVE-2014-2237
Description
The memcache token backend in OpenStack Identity (Keystone) 2013.1 through 2.013.1.4, 2013.2 through 2013.2.2, and icehouse before icehouse-3, when issuing a trust token with impersonation enabled, does not include this token in the trustee's token-index-list, which prevents the token from being invalidated by bulk token revocation and allows the trustee to bypass intended access restrictions.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
keystonePyPI | < 8.0.0a0 | 8.0.0a0 |
Affected products
7cpe:2.3:a:openstack:keystone:2013.1:*:*:*:*:*:*:*+ 5 more
- cpe:2.3:a:openstack:keystone:2013.1:*:*:*:*:*:*:*
- cpe:2.3:a:openstack:keystone:2013.1.1:*:*:*:*:*:*:*
- cpe:2.3:a:openstack:keystone:2013.1.2:*:*:*:*:*:*:*
- cpe:2.3:a:openstack:keystone:2013.1.3:*:*:*:*:*:*:*
- cpe:2.3:a:openstack:keystone:2013.1.4:*:*:*:*:*:*:*
- cpe:2.3:a:openstack:keystone:2013.2.2:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
11- github.com/advisories/GHSA-23x9-8hxr-978cghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2014-2237ghsaADVISORY
- www.openwall.com/lists/oss-security/2014/03/04/16nvdWEB
- bugs.launchpad.net/keystone/+bug/1260080nvdWEB
- github.com/openstack/keystone/commit/813d1254eb4f7a7d40009b23bbadbc4c5cc5daacghsaWEB
- github.com/openstack/keystone/commit/a411c944af78c36f2fdb87d305ba452dc52d7ed3ghsaWEB
- github.com/openstack/keystone/commit/b6f0e26da0e2ab0892a5658da281a065e668637bghsaWEB
- github.com/pypa/advisory-database/tree/main/vulns/keystone/PYSEC-2014-105.yamlghsaWEB
- rhn.redhat.com/errata/RHSA-2014-0580.htmlghsaWEB
- rhn.redhat.com/errata/RHSA-2014-0580.htmlnvd
- www.securityfocus.com/bid/65895nvd
News mentions
0No linked articles in our index yet.