CVE-2013-2013 is an information disclosure vulnerability affecting OpenStack's python-keystoneclient prior to version 0.2.4, specifically caused by the user-password-update command accepting sensitive credentials via the command-line argument. This flaw carries a low severity CVSS score of 2.1, as it requires an attacker to have local access to the system to view the process list and intercept the exposed password. Currently, there is no evidence of active exploitation or public exploit code availability in major repositories, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.2.3CPE matchmatch criteria | cpe:2.3:a:openstack:python-keystoneclient:*:*:*:*:*:*:*:* | ||
0.2.2CPE matchmatch criteria | cpe:2.3:a:openstack:python-keystoneclient:0.2.2:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:P/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.6 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.