4.3
CVSSv2

CVE-2013-2157

Published: 20/08/2013 Updated: 08/08/2019
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

OpenStack Keystone Folsom, Grizzly prior to 2013.1.3, and Havana, when using LDAP with Anonymous binding, allows remote malicious users to bypass authentication via an empty password.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

openstack keystone

Vendor Advisories

Debian Bug report logs - #712160 keystone: CVE-2013-2157 - authentication bypass when using LDAP backend Package: keystone; Maintainer for keystone is Debian OpenStack <team+openstack@trackerdebianorg>; Source for keystone is src:keystone (PTS, buildd, popcon) Reported by: Yves-Alexis Perez <corsac@debianorg> Date ...
Keystone did not always properly verify expired PKI tokens or properly authenticate users ...