© 2025-2026 PySpect
First version without a known vulnerability: 1.6.0
python-keystoneclient missing expiration check in PKI token validation
Fixed in: 0.2.4
OpenStack Nova uses insecure keystone middleware tmpdir by default
Fixed in: 0.2.4
OpenStack keystonemiddleware does not verify certificate
Fixed in: 0.11.0, 1.2.0
OpenStack keystonemiddleware and python-keystoneclient vulnerable to man-in-the-middle attacks
Fixed in: 1.6.0, 1.4.0
python-keystoneclient unsecure user password update
Fixed in: 0.2.4
python-keystoneclient vulnerable to context confusion in Keystone auth_token middleware
Fixed in: 0.7.0
OpenStack Keystone and other components vulnerable to Improper Certificate Validation
Fixed in: 0.4.0, 7.0.0a0, 8.0.0a0
Inadequate Encryption Strength in python-keystoneclient
Fixed in: 0.3.0
Insufficient Verification of Data Authenticity in python-keystoneclient
Fixed in: 0.3.0