Junglewise Threat Intelligence
CVE-2013-2013: PYSEC-2013-24 - The user-password-update command in python-keystoneclient before 0.2.4 accepts the new password in the --password argument, which allows loc
CVE-2013-2013 · Severity: low · CVSS 3.1 · Published 2013-10-01
Technologies: python-keystoneclient (PyPI). Vendors: PyPI.
Executive brief
The user-password-update command in python-keystoneclient before 0.2.4 accepts the new password in the --password argument, which allows local users to obtain sensitive information by listing the process.
Affected products
- PyPI python-keystoneclient