Python Keystoneclient

Vendor:

First CVE: Oct 1, 2013 · Active for 12 years

7
Total CVEs
More Total CVEs than 83% of tracked products
1.8
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
6.0
Avg CVSS
Higher Avg CVSS than 20% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Python Keystoneclient over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 1, 2013
12 years ago
Most Recent CVE
Dec 10, 2019
2,418 days ago

CVE Severity & Scoring

Python Keystoneclient7 CVEs
All CVEs352,231 CVEs
LowMediumCritical
Attack Vector
Local0 (0.0%)
Network2 (28.6%)
Unknown5 (71.4%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low2 (28.6%)
High0 (0.0%)
Unknown5 (71.4%)
User Interaction
None2 (28.6%)
Unknown5 (71.4%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None2 (28.6%)
Unknown5 (71.4%)

Top CVEs

Signals from CVEs in this product scope (7 CVEs).

7 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache signing bypass
Dec 10, 20199.832NONO
python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache encryption bypass
Dec 10, 20199.831NONO
The user-password-update command in python-keystoneclient before 0.2.4 accepts the new password in the --password argument, which allows local users to obtain sensitive information
Oct 1, 20132.121NONO
The s3_token middleware in OpenStack keystonemiddleware before 1.6.0 and python-keystoneclient before 1.4.0 disables certification verification when the "insecure" option is set in
Apr 17, 20154.317NONO
The auth_token middleware in the OpenStack Python client library for Keystone (aka python-keystoneclient) before 0.7.0 does not properly retrieve user tokens from memcache, which a
Apr 15, 20146.017NONO
python-keystoneclient before 0.2.4, as used in OpenStack Keystone (Folsom), does not properly check expiry for PKI tokens, which allows remote authenticated users to (1) retain use
Jan 21, 20145.516NONO
OpenStack keystonemiddleware (formerly python-keystoneclient) 0.x before 0.11.0 and 1.x before 1.2.0 disables certification verification when the "insecure" option is set in a past
Oct 2, 20144.314NONO

Exploit Exposure

Signals from CVEs in this product scope (7 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (7 CVEs).

Media Mentions

Signals from CVEs in this product scope (7 CVEs).

Top CNAs Publishing CVEs For Python Keystoneclient

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
0.3.216.01.1%00
0.3.116.01.1%00
0.3.016.01.1%00
0.2.416.01.1%00
0.2.316.01.1%00
0.2.234.51.2%00