SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2013-0282

OpenStack Keystone Grizzly before 2013.1, Folsom 2012.1.3 and earlier, and Essex does not properly check if the (1) user, (2) tenant, or (3) domain is enabled when using EC2-style authentication, which allows context-dependent attackers to bypass access…

MEDIUM 5.0EPSS 1.76%

Does this matter?

Lower severity and a low EPSS score (1.76%). Track it; it rarely justifies an emergency change on its own.

Description

OpenStack Keystone Grizzly before 2013.1, Folsom 2012.1.3 and earlier, and Essex does not properly check if the (1) user, (2) tenant, or (3) domain is enabled when using EC2-style authentication, which allows context-dependent attackers to bypass access restrictions.

CVSS 2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS
1.76% probability · 77th percentile
CISA KEV
Not listed
Weakness
CWE-287
Affected
openstack/keystone
Source
secalert@redhat.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.