python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache signing bypass
| Score | Percentile |
|---|---|
| 0.83% | 74.50% |
| Base score | Version | Severity | Vector |
|---|---|---|---|
| 9.8 | 3.1 | — |
|
| 9.3 | 4.0 | — |
|
| Type | Value |
|---|---|
| GHSA | GHSA-9vg3-cf92-h2h7 ↗ |
| CVE | CVE-2013-2167 ↗ |
| CWE id | Name |
|---|---|
| CWE-345 | Insufficient Verification of Data Authenticity |
Vulnerable version ranges and first patched releases as published by GitHub.
| Ecosystem | Package | Vulnerable range | First patched | Vulnerable functions |
|---|---|---|---|---|
| pip | python-keystoneclient | >= 0.2.3, <= 0.2.5 | 0.3.0 | — |