CVE-2013-2166: Weak Encryption
Published Dec 10, 2019
·Updated
python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache encryption bypass
Affected Software
8 affected componentsFixes available
pip/python-keystoneclient>=0.2.3<=0.2.5
0.3.0
Openstack python-keystoneclient>=0.2.3<=0.2.5
redhat Openstack=3.0
Fedoraproject Fedora=19
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Debian Debian Linux=10.0
debian/python-keystoneclient
1:4.1.1-21:5.0.1-31:5.6.0-21:5.7.0-3
Event History
Dec 10, 2019
CVE Published
via MITRE·02:19 PM
Data Sourced
via MITRE·02:19 PM
DescriptionWeakness
Oct 12, 2021
Advisory Published
via GitHub·04:31 PM
Feb 18, 2026
Data Sourced
via Debian·04:06 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is CVE-2013-2166?
CVE-2013-2166 is a vulnerability in python-keystoneclient version 0.2.3 to 0.2.5 that allows middleware memcache encryption bypass.
2
What is the severity of CVE-2013-2166?
The severity of CVE-2013-2166 is critical with a CVSS score of 9.8.
3
How does CVE-2013-2166 affect python-keystoneclient?
CVE-2013-2166 affects python-keystoneclient versions 0.2.3 to 0.2.5.
4
How can I fix CVE-2013-2166 in python-keystoneclient?
To fix CVE-2013-2166 in python-keystoneclient, upgrade to version 0.3.0 or later.
5
Are there any references for CVE-2013-2166?
Yes, you can find references for CVE-2013-2166 at: [NVD](https://nvd.nist.gov/vuln/detail/CVE-2013-2166), [GitHub](https://github.com/openstack/python-keystoneclient/commit/eeefb784f24c37d5f56a421e1ccc911cace9385e), [Red Hat](https://access.redhat.com/security/cve/cve-2013-2166).