CRITICAL
python-keystoneclient: middleware memcache encryption and signing bypass
Published Dec 10, 2019
9.3
CRITICALCVSS 4.0
EPSS 2.15%
Description
python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache encryption bypass
Affected products
-
- Version < 0.2.6StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Python-Keystoneclient | Python-Keystoneclient | n/a |
|
Configuration 1
- ≥ 0.2.3 · ≤ 0.2.5
Configuration 2
OR
- 3.0
- 19
Configuration 3
OR
- 8.0
- 9.0
- 10.0
No data.
OpenStack 3 for RHEL 6
python-keystoneclient-1:0.2.3-5.el6ost
Fixed · RHSA-2013:0992
| Product | Package | State | Advisory |
|---|---|---|---|
| OpenStack 3 for RHEL 6 | python-keystoneclient-1:0.2.3-5.el6ost | Fixed | RHSA-2013:0992 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (15)
- http://lists.fedoraproject.org/pipermail/package-announce/2013-August/113944.html x_refsource_MISCMailing ListRelease NotesThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2013-0992.html x_refsource_MISCThird Party Advisory
- http://www.openwall.com/lists/oss-security/2013/06/19/5 x_refsource_MISCIssue TrackingMailing ListThird Party Advisory
- http://www.securityfocus.com/bid/60684 x_refsource_MISCThird Party AdvisoryVDB Entry
- https://access.redhat.com/security/cve/CVE-2013-2166 Vendor Advisory
- https://access.redhat.com/security/cve/cve-2013-2166 x_refsource_MISCThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=974271 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-2166 x_refsource_MISCExploitIssue TrackingThird Party Advisory
- https://bugzilla.suse.com/show_bug.cgi?id=CVE-2013-2166 x_refsource_MISCIssue TrackingThird Party Advisory
- https://github.com/advisories/GHSA-c3xq-cj8f-7829 Advisory
- https://github.com/openstack/python-keystoneclient/commit/eeefb784f24c37d5f56a421e1ccc911cace9385e
- https://github.com/pypa/advisory-database/tree/main/vulns/python-keystoneclient/PYSEC-2019-197.yaml
- https://nvd.nist.gov/vuln/detail/CVE-2013-2166
- https://security-tracker.debian.org/tracker/CVE-2013-2166 x_refsource_MISCThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2013-2166
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Dec 10, 2019
Updated Aug 6, 2024
Reserved Feb 19, 2013
Link CVE-2013-2166
CISA Vulnrichment
GHSA-C3XQ-CJ8F-7829 Updated n/a