5
CVSSv2

CVE-2013-0247

Published: 24/02/2013 Updated: 15/11/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

OpenStack Keystone Essex 2012.1.3 and previous versions, Folsom 2012.2.3 and previous versions, and Grizzly grizzly-2 and previous versions allows remote malicious users to cause a denial of service (disk consumption) via many invalid token requests that trigger excessive generation of log entries.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

openstack keystone

canonical ubuntu linux 12.04

canonical ubuntu linux 12.10

Vendor Advisories

Synopsis Moderate: openstack-keystone security and bug fix update Type/Severity Security Advisory: Moderate Topic Updated openstack-keystone packages that fix one security issue and twobugs are now available for Red Hat OpenStack FolsomThe Red Hat Security Response Team has rated this update as having mode ...
Keystone could be made to fill server disks with error messages ...
Debian Bug report logs - #708515 keystone: CVE-2013-2014 DoS via large POST requests Package: keystone; Maintainer for keystone is Debian OpenStack <team+openstack@trackerdebianorg>; Source for keystone is src:keystone (PTS, buildd, popcon) Reported by: Nico Golde <nion@debianorg> Date: Thu, 16 May 2013 09:27:02 U ...
Debian Bug report logs - #700948 keystone: CVE-2013-1664 (DoS in xml entitiy parsing) and CVE-2013-1665 (nformation leak via xml entity parsing) Package: keystone; Maintainer for keystone is Debian OpenStack <team+openstack@trackerdebianorg>; Source for keystone is src:keystone (PTS, buildd, popcon) Reported by: Thomas Goi ...
Debian Bug report logs - #699835 keystone: CVE-2013-0247: Keystone denial of service through invalid token requests Package: keystone; Maintainer for keystone is Debian OpenStack <team+openstack@trackerdebianorg>; Source for keystone is src:keystone (PTS, buildd, popcon) Reported by: Salvatore Bonaccorso <carnil@debian ...
Debian Bug report logs - #700947 CVE-2013-0282: Ensure EC2 users and tenant are enabled Package: keystone; Maintainer for keystone is Debian OpenStack <team+openstack@trackerdebianorg>; Source for keystone is src:keystone (PTS, buildd, popcon) Reported by: Thomas Goirand <zigo@debianorg> Date: Tue, 19 Feb 2013 16: ...