---
id: CVE-2013-1865
aliases:
  - PYSEC-2013-39
  - GHSA-22q6-wwq7-2jj9
title: >-
  OpenStack Keystone Folsom (2012.2) does not properly perform revocation checks
  for Keystone PKI tokens when done through a server, which …
summary: >-
  OpenStack Keystone Folsom (2012.2) does not properly perform revocation checks
  for Keystone PKI tokens when done through a server, which allows remote
  attackers to bypass intended access restrictions via a revoked PKI token.
severity: none
vendor: keystone
product: keystone
ecosystem: pip
affected:
  - 'keystone >= 2012.2, < 2012.2.4'
patched:
  - keystone 2012.2.4
published: '2013-03-22'
updated: '2026-07-01'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/PYSEC-2013-39'
references:
  - url: 'https://review.openstack.org/#/c/24906/'
  - url: 'http://www.securityfocus.com/bid/58616'
  - url: 'https://bugs.launchpad.net/keystone/+bug/1129713'
  - url: 'http://www.ubuntu.com/usn/USN-1772-1'
  - url: 'http://osvdb.org/91532'
  - url: 'http://www.openwall.com/lists/oss-security/2013/03/20/13'
  - url: 'http://secunia.com/advisories/52657'
  - url: 'http://lists.opensuse.org/opensuse-updates/2013-04/msg00000.html'
  - url: 'http://rhn.redhat.com/errata/RHSA-2013-0708.html'
  - url: >-
      http://lists.fedoraproject.org/pipermail/package-announce/2013-April/101719.html
  - url: 'https://github.com/advisories/GHSA-22q6-wwq7-2jj9'
tags:
  - osv
  - pip
epss: 0.0263
epssPercentile: 0.84782
ingestedAt: '2026-07-08T18:25:55.319Z'
---

## Overview

OpenStack Keystone Folsom (2012.2) does not properly perform revocation checks for Keystone PKI tokens when done through a server, which allows remote attackers to bypass intended access restrictions via a revoked PKI token.

## Affected packages

- `keystone >= 2012.2, < 2012.2.4`

## Remediation

Upgrade to a patched release:

- `keystone 2012.2.4`
