CVE-2013-2167: Critical severity Openstack python-keystoneclient vulnerability
Published Dec 10, 2019
·Updated
python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache signing bypass
Affected Software
7 affected componentsFixes available
pip/python-keystoneclient>=0.2.3<=0.2.5
0.3.0
Openstack python-keystoneclient>=0.2.3<=0.2.5
redhat Openstack=3.0
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Debian Debian Linux=10.0
debian/python-keystoneclient
1:4.1.1-21:5.0.1-31:5.6.0-21:5.7.0-3
Remediation
Patch Available
Event History
Dec 10, 2019
CVE Published
via MITRE·02:22 PM
Data Sourced
via MITRE·02:22 PM
DescriptionWeakness
Mar 10, 2020
Advisory Published
via GitHub·08:39 PM
Feb 18, 2026
Data Sourced
via Debian·04:06 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2013-2167?
The severity of CVE-2013-2167 is critical with a score of 9.8.
2
Which version of python-keystoneclient is affected by CVE-2013-2167?
python-keystoneclient version 0.2.3 to 0.2.5 is affected by CVE-2013-2167.
3
How can I fix CVE-2013-2167?
To fix CVE-2013-2167, upgrade python-keystoneclient to version 0.3.0 or higher.
4
Are there any references for CVE-2013-2167?
Yes, you can find references for CVE-2013-2167 at the following links: [NVD](https://nvd.nist.gov/vuln/detail/CVE-2013-2167), [GitHub](https://github.com/openstack/python-keystoneclient/commit/eeefb784f24c37d5f56a421e1ccc911cace9385e), [RedHat](https://access.redhat.com/security/cve/cve-2013-2167).
5
What is the Common Weakness Enumeration (CWE) for CVE-2013-2167?
The Common Weakness Enumeration (CWE) for CVE-2013-2167 is CWE-345.