[Openstack-devel] Bug#709535: python-keystoneclient: CVE-2013-2013: OpenStack keystone password disclosure on command line

Salvatore Bonaccorso carnil at debian.org
Thu May 23 21:18:06 UTC 2013


Package: python-keystoneclient
Version: 2012.1-3
Severity: important
Tags: security patch upstream

Hi,

the following vulnerability was published for python-keystoneclient.

CVE-2013-2013[0]:
OpenStack keystone password disclosure on command line

Upstream patch is at [1] and introduces the ability for user password to
be updated via a command prompt.

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] http://security-tracker.debian.org/tracker/CVE-2013-2013
[1] https://review.openstack.org/#/c/28702/ 

Regards,
Salvatore



More information about the Openstack-devel mailing list