Vulnerability Details CVE-2013-4222
OpenStack Identity (Keystone) Folsom, Grizzly 2013.1.3 and earlier, and Havana before havana-3 does not properly revoke user tokens when a tenant is disabled, which allows remote authenticated users to retain access via the token.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.006
EPSS Ranking 67.5%
CVSS Severity
CVSS v2 Score 6.5
Products affected by CVE-2013-4222
-
cpe:2.3:a:openstack:keystone:2013.1
-
cpe:2.3:a:openstack:keystone:2013.1.1
-
cpe:2.3:a:openstack:keystone:2013.1.2
-
cpe:2.3:a:openstack:keystone:2013.1.3
-
cpe:2.3:a:redhat:openstack:3.0
-
cpe:2.3:o:canonical:ubuntu_linux:12.10
-
cpe:2.3:o:canonical:ubuntu_linux:13.04
-
cpe:2.3:o:fedoraproject:fedora:20