CVE-2013-2013: Openstack Python-Keystoneclient

Low severity, CVSS 2.1. EPSS: 0.4% chance of exploitation in the next 30 days.

The user-password-update command in python-keystoneclient before 0.2.4 accepts the new password in the --password argument, which allows local users to obtain sensitive information by listing the process.

Affected products

  • Openstack Python-Keystoneclient: up to and including 0.2.3; version 0.2.2 only

Published 2013-10-01. Last modified 2026-06-16.