MEDIUM 4.3 PyPI

OpenStack Identity (Keystone) improper revoking of the authentication token when deleting a user

GHSA-hj89-qmx9-8qmh · CVE-2013-2059 · PYSEC-2013-41

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

OpenStack Identity (Keystone) Folsom 2012.2.4 and earlier, Grizzly before 2013.1.1, and Havana does not immediately revoke the authentication token when deleting a user through the Keystone v2 API, which allows remote authenticated users to retain access via the token.

Ready to move

Start Securing

Free, no credit card | First findings in minutes