CVE-2013-2013

Description

The user-password-update command in python-keystoneclient before 0.2.4 accepts the new password in the --password argument, which allows local users to obtain sensitive information by listing the process.

Risk Information

Base Score
2.9
MODERATE
Vector
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS Score
Exploitation Probability
0.065

Associated Vulnerability

VulnerabilityOS Platform
Cumulative Security Update for Internet Explorer for Windows XP (KB2817183)Windows
Cumulative Security Update for Internet Explorer for Windows Server 2003 (KB2817183)Windows
Cumulative Security Update for Internet Explorer for Windows Server 2003 x64 Edition (KB2817183)Windows
Cumulative Security Update for Internet Explorer 7 for Windows XP (KB2817183)Windows
Cumulative Security Update for Internet Explorer 7 for Windows Server 2003 (KB2817183)Windows
Cumulative Security Update for Internet Explorer 7 in Windows Vista (KB2817183)Windows
Cumulative Security Update for Internet Explorer 7 in Windows Server 2008 (KB2817183)Windows
Cumulative Security Update for Internet Explorer 7 for Windows XP x64 Edition (KB2817183)Windows
Cumulative Security Update for Internet Explorer 7 for Windows Server 2003 x64 Edition (KB2817183)Windows
Cumulative Security Update for Internet Explorer 7 in Windows Vista x64 Edition (KB2817183)Windows
Cumulative Security Update for Internet Explorer 7 in Windows Server 2008 x64 Edition (KB2817183)Windows
Cumulative Security Update for Internet Explorer 8 for Windows XP (KB2817183)Windows
Cumulative Security Update for Internet Explorer 8 for Windows Server 2003 (KB2817183)Windows
Cumulative Security Update for Internet Explorer 8 in Windows Vista (KB2817183)Windows
Cumulative Security Update for Internet Explorer 8 in Windows Server 2008 (KB2817183)Windows
Cumulative Security Update for Internet Explorer 8 in Windows 7 (KB2817183) x86 based systemsWindows
Cumulative Security Update for Internet Explorer 8 in Windows 7 (KB2817183) x86 based systems for SP1Windows
Cumulative Security Update for Internet Explorer 8 for Windows XP x64 Edition (KB2817183)Windows
Cumulative Security Update for Internet Explorer 8 for Windows Server 2003 x64 Edition (KB2817183)Windows
Cumulative Security Update for Internet Explorer 8 in Windows Vista x64 Edition (KB2817183)Windows
Cumulative Security Update for Internet Explorer 8 in Windows Server 2008 x64 Edition (KB2817183)Windows
Cumulative Security Update for Internet Explorer 8 in Windows 7 x64 Edition (KB2817183)Windows
Cumulative Security Update for Internet Explorer 8 in Windows 7 x64 Edition (KB2817183) for SP1Windows
Cumulative Security Update for Internet Explorer 8 in Windows Server 2008 R2 x64 Edition (KB2817183)Windows
Cumulative Security Update for Internet Explorer 8 in Windows Server 2008 R2 x64 Edition (KB2817183) for SP1Windows
Cumulative Security Update for Internet Explorer 9 in Windows Vista (KB2817183)Windows
Cumulative Security Update for Internet Explorer 9 in Windows Server 2008 (KB2817183)Windows
Cumulative Security Update for Internet Explorer 9 in Windows 7 (KB2817183) x86 based systemsWindows
Cumulative Security Update for Internet Explorer 9 in Windows 7 (KB2817183) x86 based systems for SP1Windows
Cumulative Security Update for Internet Explorer 9 in Windows Vista x64 Edition (KB2817183)Windows
Cumulative Security Update for Internet Explorer 9 in Windows Server 2008 x64 Edition (KB2817183)Windows
Cumulative Security Update for Internet Explorer 9 in Windows 7 x64 Edition (KB2817183)Windows
Cumulative Security Update for Internet Explorer 9 in Windows 7 x64 Edition (KB2817183) for SP1Windows
Cumulative Security Update for Internet Explorer 9 in Windows Server 2008 R2 x64 Edition (KB2817183)Windows
Cumulative Security Update for Internet Explorer 9 in Windows Server 2008 R2 x64 Edition (KB2817183)Windows
Cumulative Security Update for Internet Explorer 10 in Windows 7 (KB2817183)Windows
Cumulative Security Update for Internet Explorer 10 in Windows 8 (KB2817183)Windows
Cumulative Security Update for Internet Explorer 10 in Windows 7 x64 Edition (KB2817183)Windows
Cumulative Security Update for Internet Explorer 10 in Windows Server 2008 R2 x64 Edition (KB2817183)Windows
Cumulative Security Update for Internet Explorer 10 in Windows 8 x64 Edition (KB2817183)Windows
Cumulative Security Update for Internet Explorer 10 in Windows Server 2012 x64 Edition (KB2817183)Windows
Vulnerabilities CVE-2013-2013,CVE-2013-2030,CVE-2013-2104 are fixed in Python-python-keystoneclient 0.2.4Windows
Vulnerabilities CVE-2013-2013,CVE-2013-2030,CVE-2013-2104 are fixed in Python-python-keystoneclient for linux 0.2.4Linux

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-13351Cumulative Security Update for Internet Explorer for Windows XP (KB2817183)
PATCH-13352Cumulative Security Update for Internet Explorer for Windows Server 2003 (KB2817183)
PATCH-13354Cumulative Security Update for Internet Explorer for Windows Server 2003 x64 Edition (KB2817183)
PATCH-13355Cumulative Security Update for Internet Explorer 7 for Windows XP (KB2817183)
PATCH-13356Cumulative Security Update for Internet Explorer 7 for Windows Server 2003 (KB2817183)
PATCH-13357Cumulative Security Update for Internet Explorer 7 in Windows Vista (KB2817183)
PATCH-13358Cumulative Security Update for Internet Explorer 7 in Windows Server 2008 (KB2817183)
PATCH-13359Cumulative Security Update for Internet Explorer 7 for Windows XP x64 Edition (KB2817183)
PATCH-13360Cumulative Security Update for Internet Explorer 7 for Windows Server 2003 x64 Edition (KB2817183)
PATCH-13361Cumulative Security Update for Internet Explorer 7 in Windows Vista x64 Edition (KB2817183)
PATCH-13362Cumulative Security Update for Internet Explorer 7 in Windows Server 2008 x64 Edition (KB2817183)
PATCH-13363Cumulative Security Update for Internet Explorer 8 for Windows XP (KB2817183)
PATCH-13364Cumulative Security Update for Internet Explorer 8 for Windows Server 2003 (KB2817183)
PATCH-13365Cumulative Security Update for Internet Explorer 8 in Windows Vista (KB2817183)
PATCH-13366Cumulative Security Update for Internet Explorer 8 in Windows Server 2008 (KB2817183)
PATCH-13367Cumulative Security Update for Internet Explorer 8 in Windows 7 (KB2817183)
PATCH-13368Cumulative Security Update for Internet Explorer 8 in Windows 7 (KB2817183)
PATCH-13369Cumulative Security Update for Internet Explorer 8 for Windows XP x64 Edition (KB2817183)
PATCH-13370Cumulative Security Update for Internet Explorer 8 for Windows Server 2003 x64 Edition (KB2817183)
PATCH-13371Cumulative Security Update for Internet Explorer 8 in Windows Vista x64 Edition (KB2817183)
PATCH-13372Cumulative Security Update for Internet Explorer 8 in Windows Server 2008 x64 Edition (KB2817183)
PATCH-13373Cumulative Security Update for Internet Explorer 8 in Windows 7 x64 Edition (KB2817183)
PATCH-13374Cumulative Security Update for Internet Explorer 8 in Windows 7 x64 Edition (KB2817183)
PATCH-13375Cumulative Security Update for Internet Explorer 8 in Windows Server 2008 R2 x64 Edition (KB2817183)
PATCH-13376Cumulative Security Update for Internet Explorer 8 in Windows Server 2008 R2 x64 Edition (KB2817183)
PATCH-13377Cumulative Security Update for Internet Explorer 9 in Windows Vista (KB2817183)
PATCH-13379Cumulative Security Update for Internet Explorer 9 in Windows 7 (KB2817183)
PATCH-13380Cumulative Security Update for Internet Explorer 9 in Windows 7 (KB2817183)
PATCH-13381Cumulative Security Update for Internet Explorer 9 in Windows Vista x64 Edition (KB2817183)
PATCH-13382Cumulative Security Update for Internet Explorer 9 in Windows Server 2008 x64 Edition (KB2817183)
PATCH-13383Cumulative Security Update for Internet Explorer 9 in Windows 7 x64 Edition (KB2817183)
PATCH-13384Cumulative Security Update for Internet Explorer 9 in Windows 7 x64 Edition (KB2817183)
PATCH-13385Cumulative Security Update for Internet Explorer 9 in Windows Server 2008 R2 x64 Edition (KB2817183)
PATCH-13387Cumulative Security Update for Internet Explorer 10 in Windows 7 (KB2817183)
PATCH-13388Cumulative Security Update for Internet Explorer 10 in Windows 8 (KB2817183)
PATCH-13390Cumulative Security Update for Internet Explorer 10 in Windows Server 2008 R2 x64 Edition (KB2817183)
PATCH-13391Cumulative Security Update for Internet Explorer 10 in Windows 8 x64 Edition (KB2817183)
PATCH-13392Cumulative Security Update for Internet Explorer 10 in Windows Server 2012 x64 Edition (KB2817183)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234