VDB
CVE-2013-2006
CVE-2013-2006
PUBLISHED
CVSS 2.0999999046325684 LOW
OpenStack Identity (Keystone) Grizzly 2013.1.1, when DEBUG mode logging is enabled, logs the (1) admin_token and (2) LDAP password in plaintext, which allows local users to obtain sensitive by reading the log file.
EPSS 0.61% · 46.5th percentile
Risk Scores
CVSS 2.0
2.0999999046325684
EPSS Score
0.61%
46.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| PyPI | keystone | 0 |
| openstack | keystone | 2013.1.1 |
Timeline
- May 21, 2013 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 21, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 19, 2022 EPSS Score
- Feb 3, 2023 EPSS Score
- Feb 13, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- Jul 18, 2023 EPSS Score
References
- https://github.com/openstack/keystone/commit/c5037dd6b82909efaaa8720e8cfa8bdb8b4a0edd url
- 59411 vdb
- FEDORA-2013-8048 vendor-advisory
- https://bugs.launchpad.net/ossn/+bug/1168252 url
- RHSA-2013:0806 vendor-advisory
- https://bugs.launchpad.net/keystone/+bug/1172195 url
- [oss-security] 20130423 CVE-2013-2006 OpenStack keystone LDAP password disclosure in log files mailing-list
- FEDORA-2013-8023 vendor-advisory
- [oss-security] 20130424 Re: CVE-2013-2006 OpenStack keystone LDAP password disclosure in log files mailing-list
- https://nvd.nist.gov/vuln/detail/CVE-2013-2006 advisory
- https://github.com/openstack/keystone/commit/d43e2a51a1ed7adbed3c5ddf001d46bc4a824ae8 url
- https://github.com/openstack/keystone package
- https://github.com/pypa/advisory-database/tree/main/vulns/keystone/PYSEC-2013-40.yaml url