CVE-2013-2059: Medium severity keystone vulnerability
OpenStack Identity (Keystone) Folsom 2012.2.4 and earlier, Grizzly before 2013.1.1, and Havana does not immediately revoke the authentication token when deleting a user through the Keystone v2 API, which allows remote authenticated users to retain access via the token.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-2059?
CVE-2013-2059 is considered a medium severity vulnerability due to the potential for unauthorized access to user accounts.
How do I fix CVE-2013-2059?
To fix CVE-2013-2059, users should upgrade to OpenStack Keystone version 2013.1.1 or later.
What is the impact of CVE-2013-2059?
The impact of CVE-2013-2059 allows remote authenticated users to retain access to the system even after their user account has been deleted.
Which versions are affected by CVE-2013-2059?
CVE-2013-2059 affects OpenStack Identity (Keystone) versions 2012.2.4 and earlier, Grizzly before 2013.1.1, and Havana.
Is there a workaround for CVE-2013-2059?
While the primary mitigation for CVE-2013-2059 is upgrading, admins may consider manually revoking tokens when deleting a user as a temporary workaround.