depscope
Packages
IntegrateAPI DocsCuratorBenchmarkCoverage
Sign inGet API access
depscope/pypi/keystone

keystone

pypiv29.0.1

OpenStack Identity

License Apache-2.0permissive61 versions33 deps14,397 weekly dl
68
/ 100
Health
update required

[email protected] has vulnerabilities — update to latest

Update to >= f9d4766249a72d8f88d75dcf1575b28dd3496681 to fix known vulnerabilities

  • Moderate health score (68/100) — verify manually
  • 1 high severity vulnerabilities
Health breakdown0 – 100
25/25
maintenance
10/20
popularity
18/25
security
15/15
maturity
0/15
community
Vulnerabilities
4
1 high1 medium2 low
Advisories (4)
SeverityIDSummaryFixed in
highCVE-2012-3542OpenStack Keystone Allows Remote User Account Creation2012.1
mediumCVE-2012-4413OpenStack Keystone does not invalidate existing tokens when granting or revoking roles2012.1.3
unknownCVE-2012-3542OpenStack Keystone, as used in OpenStack Folsom before folsom-rc1 and OpenStack Essex (2012.1), allows remote attackers to add an arbitrary user to an arbitrary tenant via a request to update the user's default tenant to the administrative API. NOTE: this identifier was originally incorrectly assigned to an open redirect issue, but the correct identifier for that issue is CVE-2012-3540.c13d0ba606f7b2bdc609a7f388334e5efec3f3aa
unknownCVE-2012-5563OpenStack Keystone, as used in OpenStack Folsom 2012.2, does not properly implement token expiration, which allows remote authenticated users to bypass intended authorization restrictions by creating new tokens through token chaining. NOTE: this issue exists because of a CVE-2012-3426 regression.f9d4766249a72d8f88d75dcf1575b28dd3496681

Health History

Dependency Tree

License Audit

Dependencies (33)
pbrWebObFlaskFlask-RESTfulcryptographySQLAlchemystevedorepython-keystoneclientkeystonemiddlewarebcryptoslo.cacheoslo.configoslo.contextoslo.messagingoslo.dboslo.i18noslo.logoslo.middlewareoslo.policyoslo.serializationoslo.upgradecheckoslo.utilsoauthlibpysaml2PyJWTdogpile.cachejsonschemapycadfmsgpackosprofilerWerkzeugpython-ldapldappool
API access

Get this data programmatically — free, no authentication.

curl https://depscope.dev/api/check/pypi/keystone
More from pypi
boto3packagingidnacertifiurllib3requests
Browse all pypi packages →

Last updated · 2026-04-16T09:33:42.571591Z

DepScope

Package intelligence for AI agents. 19 ecosystems.

Resources
API DocumentationHallucination BenchmarkFor EnterpriseSwagger / OpenAPIPopular PackagesCoverageAI Plugin SetupWatch the pitch (60s)
Legal
Legal hubPrivacy PolicyTerms of ServiceCookie PolicyAcceptable UseAttributionDPASub-processorsSecurityImprintContact中文
© 2026 Cuttalo srl — Italy · VAT IT03242390734Built for AI agents