CVE-2013-1865
CVE-2013-1865 is a medium-severity vulnerability in Openstack Folsom with a CVSS 2.0 base score of 6.8. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-287.
Key facts
- Severity: Medium (CVSS 2.0 base score 6.8)
- EPSS exploit prediction: 3% (85th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-287
- Affected product: Openstack Folsom
- Published:
- Last modified:
Description
OpenStack Keystone Folsom (2012.2) does not properly perform revocation checks for Keystone PKI tokens when done through a server, which allows remote attackers to bypass intended access restrictions via a revoked PKI token.
Frequently asked questions
- What is CVE-2013-1865?
- OpenStack Keystone Folsom (2012.2) does not properly perform revocation checks for Keystone PKI tokens when done through a server, which allows remote attackers to bypass intended access restrictions via a revoked PKI token.
- How severe is CVE-2013-1865?
- CVE-2013-1865 has a CVSS 2.0 base score of 6.8, rated medium severity.
- Is CVE-2013-1865 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 3% (85th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2013-1865?
- CVE-2013-1865 primarily affects Openstack Folsom. In total, 2 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2013-1865?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2013-1865 published?
- CVE-2013-1865 was published on 2013-03-22 and last updated on 2026-06-16.
References
- http://lists.fedoraproject.org/pipermail/package-announce/2013-April/101719.html
- http://lists.opensuse.org/opensuse-updates/2013-04/msg00000.html
- http://osvdb.org/91532
- http://rhn.redhat.com/errata/RHSA-2013-0708.html
- http://secunia.com/advisories/52657
- http://www.openwall.com/lists/oss-security/2013/03/20/13
- http://www.securityfocus.com/bid/58616
- http://www.ubuntu.com/usn/USN-1772-1
- https://bugs.launchpad.net/keystone/+bug/1129713
- https://review.openstack.org/#/c/24906/
Affected products (2)
- cpe:2.3:a:openstack:folsom:2012.2:*:*:*:*:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:12.10:*:*:*:*:*:*:*
More vulnerabilities in Openstack Folsom
- CVE-2013-0261 — High (CVSS 8.8): A flaw was found in PackStack. A local user could exploit a symlink attack on a temporary file with a predictable name…
- CVE-2013-0335 — High (CVSS 7.6): OpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to gain access…
- CVE-2013-2161 — High (CVSS 7.5): XML injection vulnerability in account/utils.py in OpenStack Swift Folsom, Grizzly, and Havana allows attackers to…
- CVE-2013-0208 — Medium (CVSS 6.5): The boot-from-volume feature in OpenStack Compute (Nova) Folsom and Essex, when using nova-volumes, allows remote…
- CVE-2013-4497 — Medium (CVSS 6.4): The XenAPI backend in OpenStack Compute (Nova) Folsom, Grizzly, and Havana before 2013.2 does not properly apply…
- CVE-2013-0266 — Medium (CVSS 5.5): A flaw was found in the `puppetlabs-cinder` module, as used in PackStack. This vulnerability is due to incorrect file…
All CVEs affecting Openstack Folsom →
Other CWE-287 (Improper Authentication) vulnerabilities
- CVE-2026-101077 — Critical (CVSS 10.0): A flaw has been found in Netcore NR289-GE 1.4.5102. This impacts the function process_request of the component boa_temp…
- CVE-2026-100886 — Critical (CVSS 10.0): A vulnerability was identified in Seetong T8108, T8108P, T8116 and T8232 4.6.1.4-build202604241011. The affected…
- CVE-2026-77244 — Critical (CVSS 10.0): MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0,…
- CVE-2026-94493 — Critical (CVSS 10.0): A vulnerability was detected in Gigatech PDV5701 1.0.31_240305_112640. This issue affects some unknown processing of…
- CVE-2026-83099 — Critical (CVSS 10.0): Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode).…
- CVE-2026-83059 — Critical (CVSS 10.0): Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server).…
Browse all CWE-287 (Improper Authentication) vulnerabilities →