HIGH 7.5 PyPI

python-keystoneclient missing expiration check in PKI token validation

GHSA-4rrr-j7ff-r844 · CVE-2013-2104 · PYSEC-2014-69

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

python-keystoneclient before 0.2.4, as used in OpenStack Keystone (Folsom), does not properly check expiry for PKI tokens, which allows remote authenticated users to (1) retain use of a token after it has expired, or (2) use a revoked token once it expires.

Ready to move

Start Securing

Free, no credit card | First findings in minutes