MEDIUM 5.3 PyPI

OpenStack Keystone Improper Authentication vulnerability

GHSA-22q6-wwq7-2jj9 · CVE-2013-1865 · PYSEC-2013-39

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

OpenStack Keystone Folsom (2012.2) does not properly perform revocation checks for Keystone PKI tokens when done through a server, which allows remote attackers to bypass intended access restrictions via a revoked PKI token.

Ready to move

Start Securing

Free, no credit card | First findings in minutes