CVE-2013-4294
Summary
| CVE | CVE-2013-4294 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2013-09-23 20:55:07 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | The (1) mamcache and (2) KVS token backends in OpenStack Identity (Keystone) Folsom 2012.2.x and Grizzly before 2013.1.4 do not properly compare the PKI token revocation list with PKI tokens, which allow remote attackers to bypass intended access restrictions via a revoked PKI token. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:L/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Openstack | Keystone | 2012.2 | All | All | All |
| Application | Openstack | Keystone | 2012.2.1 | All | All | All |
| Application | Openstack | Keystone | 2012.2.2 | All | All | All |
| Application | Openstack | Keystone | 2012.2.3 | All | All | All |
| Application | Openstack | Keystone | 2012.2.4 | All | All | All |
| Application | Openstack | Keystone | 2013.1 | All | All | All |
| Application | Openstack | Keystone | 2013.1.1 | All | All | All |
| Application | Openstack | Keystone | 2013.1.2 | All | All | All |
| Application | Openstack | Keystone | 2013.1.3 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| osvdb.org/97237 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| USN-2002-1: Keystone vulnerabilities | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| oss-sec: [OSSA 2013-025] Token revocation failure using Keystone memcache/KVS backends (CVE-2013-4294) | af854a3a-2127-422b-91ae-364da2661108 | seclists.org | Patch |
| About Secunia Research | Flexera | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Bug #1202952 “[OSSA 2013-025] PKI tokens are never revoked using...” : Bugs : OpenStack Identity (keystone) | af854a3a-2127-422b-91ae-364da2661108 | bugs.launchpad.net | Vendor Advisory |
| Red Hat Customer Portal | MITRE | access.redhat.com | |
| CVE-2013-4294 - Red Hat Customer Portal | MITRE | access.redhat.com | |
| 1004452 – (CVE-2013-4294) CVE-2013-4294 OpenStack: Keystone Token revocation failure using Keystone memcache/KVS backends | MITRE | bugzilla.redhat.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.