Junglewise Threat Intelligence

CVE-2013-2013: PYSEC-2013-24 - The user-password-update command in python-keystoneclient before 0.2.4 accepts the new password in the --password argument, which allows loc

CVE-2013-2013 · Severity: low · CVSS 3.1 · Published 2013-10-01

Technologies: python-keystoneclient (PyPI). Vendors: PyPI.

Executive brief

The user-password-update command in python-keystoneclient before 0.2.4 accepts the new password in the --password argument, which allows local users to obtain sensitive information by listing the process.

Affected products

  • PyPI python-keystoneclient

Related threats