{"id":"CVE-2013-0282","aliases":["GHSA-8833-qrvm-wc3h","PYSEC-2026-652"],"title":"OpenStack Keystone allows context-dependent attackers to bypass access restrictions","summary":"OpenStack Keystone allows context-dependent attackers to bypass access restrictions","severity":"medium","vendor":"keystone","product":"keystone","ecosystem":"pip","affected":["keystone < 8.0.0a0"],"patched":["keystone 8.0.0a0"],"published":"2022-05-05","updated":"2026-07-06","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-8833-qrvm-wc3h","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2013-0282"},{"url":"https://github.com/openstack/keystone/commit/7402f5ef994599653bdbb3ed5ff1a2b8c3e72b9f"},{"url":"https://github.com/openstack/keystone/commit/9572bfc393f66f5ce3b44c0a77a9e29cc0374c6f"},{"url":"https://github.com/openstack/keystone/commit/f0b4d300db5cc61d4f079f8bce9da8e8bea1081a"},{"url":"https://bugs.launchpad.net/keystone/+bug/1121494"},{"url":"https://launchpad.net/keystone/+milestone/2012.2.4"},{"url":"https://launchpad.net/keystone/grizzly/2013.1"},{"url":"https://review.openstack.org/#/c/22319"},{"url":"https://review.openstack.org/#/c/22320"},{"url":"https://review.openstack.org/#/c/22321"},{"url":"http://www.openwall.com/lists/oss-security/2013/02/19/3"}],"tags":["osv","pip"],"epss":0.01761,"epssPercentile":0.76698,"ingestedAt":"2026-07-08T18:25:47.324Z","slug":"CVE-2013-0282","body":"## Overview\n\nOpenStack Keystone Grizzly before 2013.1, Folsom 2012.1.3 and earlier, and Essex does not properly check if the (1) user, (2) tenant, or (3) domain is enabled when using EC2-style authentication, which allows context-dependent attackers to bypass access restrictions.\n\n## Affected packages\n\n- `keystone < 8.0.0a0`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `keystone 8.0.0a0`","depth":"sunlit","depthScore":28,"depthScoreParts":{"impact":27.5,"likelihood":0.4,"exploitation":0,"ransomware":0},"changes":[]}