Comment 5 for bug 938315

Assigned a CVE for this as per

While auditing OpenStack bugs for flaws needing CVE's I came across
this (as of yet unfixed) one:

[root@...s ~]# keystone user-password-update --user=jake
usage: keystone user-password-update --pass <password> <user-id>
keystone user-password-update: error: too few arguments

This class of vuln typically gets a CVE.

CVE text:

OpenStack keystone places a username and password on the command line,
which allows local users to obtain credentials by listing the process.

Please use CVE-2013-2013 for this issue.