PYSEC-2014-70

See a problem?
Import Source
https://github.com/pypa/advisory-database/blob/main/vulns/python-keystoneclient/PYSEC-2014-70.yaml
JSON Data
https://api.test.osv.dev/v1/vulns/PYSEC-2014-70
Aliases
Published
2014-04-15T14:55:00Z
Modified
2023-11-01T04:45:25.349478Z
Summary
[none]
Details

The auth_token middleware in the OpenStack Python client library for Keystone (aka python-keystoneclient) before 0.7.0 does not properly retrieve user tokens from memcache, which allows remote authenticated users to gain privileges in opportunistic circumstances via a large number of requests, related to an "interaction between eventlet and python-memcached."

References

Affected packages

PyPI / python-keystoneclient

Package

Name
python-keystoneclient
View open source insights on deps.dev
Purl
pkg:pypi/python-keystoneclient

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.7.0

Affected versions

0.*

0.1.1
0.1.2
0.1.3
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
0.4.2
0.5.0
0.5.1
0.6.0