5
CVSSv2

CVE-2013-0270

Published: 12/04/2013 Updated: 16/11/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

OpenStack Keystone Grizzly prior to 2013.1, Folsom, and possibly earlier allows remote malicious users to cause a denial of service (CPU and memory consumption) via a large HTTP request, as demonstrated by a long tenant_name when requesting a token.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

openstack keystone 2013.1

openstack keystone

Vendor Advisories

Synopsis Moderate: openstack-keystone security and bug fix update Type/Severity Security Advisory: Moderate Topic Updated openstack-keystone packages that fix two security issues andvarious bugs are now available for Red Hat OpenStack FolsomThe Red Hat Security Response Team has rated this update as having ...
Debian Bug report logs - #708515 keystone: CVE-2013-2014 DoS via large POST requests Package: keystone; Maintainer for keystone is Debian OpenStack <team+openstack@trackerdebianorg>; Source for keystone is src:keystone (PTS, buildd, popcon) Reported by: Nico Golde <nion@debianorg> Date: Thu, 16 May 2013 09:27:02 U ...
Debian Bug report logs - #699835 keystone: CVE-2013-0247: Keystone denial of service through invalid token requests Package: keystone; Maintainer for keystone is Debian OpenStack <team+openstack@trackerdebianorg>; Source for keystone is src:keystone (PTS, buildd, popcon) Reported by: Salvatore Bonaccorso <carnil@debian ...