VulnerabilityModified
CVE-2013-0282
OpenStack Keystone Grizzly before 2013.1, Folsom 2012.1.3 and earlier, and Essex does not properly check if the (1) user, (2) tenant, or (3) domain is enabled when using EC2-style authentication, which allows context-dependent attackers to bypass access…
MEDIUM 5.0EPSS 1.76%
Does this matter?
Lower severity and a low EPSS score (1.76%). Track it; it rarely justifies an emergency change on its own.
Description
OpenStack Keystone Grizzly before 2013.1, Folsom 2012.1.3 and earlier, and Essex does not properly check if the (1) user, (2) tenant, or (3) domain is enabled when using EC2-style authentication, which allows context-dependent attackers to bypass access restrictions.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 1.76% probability · 77th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- openstack/keystone
- Source
- secalert@redhat.com
References
- http://www.openwall.com/lists/oss-security/2013/02/19/3Third Party Advisory
- https://bugs.launchpad.net/keystone/+bug/1121494Third Party Advisory
- https://launchpad.net/keystone/+milestone/2012.2.4Third Party Advisory
- https://launchpad.net/keystone/grizzly/2013.1Third Party Advisory
- https://review.openstack.org/#/c/22319/Vendor Advisory
- https://review.openstack.org/#/c/22320/Vendor Advisory
- https://review.openstack.org/#/c/22321/Vendor Advisory
- http://www.openwall.com/lists/oss-security/2013/02/19/3Third Party Advisory
- https://bugs.launchpad.net/keystone/+bug/1121494Third Party Advisory
- https://launchpad.net/keystone/+milestone/2012.2.4Third Party Advisory
- https://launchpad.net/keystone/grizzly/2013.1Third Party Advisory
- https://review.openstack.org/#/c/22319/Vendor Advisory
- https://review.openstack.org/#/c/22320/Vendor Advisory
- https://review.openstack.org/#/c/22321/Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.