VulnerabilityModified
CVE-2013-2157
OpenStack Keystone Folsom, Grizzly before 2013.1.3, and Havana, when using LDAP with Anonymous binding, allows remote attackers to bypass authentication via an empty password.
MEDIUM 4.3EPSS 3.13%
Does this matter?
Lower severity and a low EPSS score (3.13%). Track it; it rarely justifies an emergency change on its own.
Description
OpenStack Keystone Folsom, Grizzly before 2013.1.3, and Havana, when using LDAP with Anonymous binding, allows remote attackers to bypass authentication via an empty password.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 3.13% probability · 87th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- openstack/keystone
- Source
- secalert@redhat.com
References
- http://rhn.redhat.com/errata/RHSA-2013-0994.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2013-1083.htmlThird Party Advisory
- http://www.openwall.com/lists/oss-security/2013/06/13/3Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/60545Third Party Advisory, VDB Entry
- http://rhn.redhat.com/errata/RHSA-2013-0994.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2013-1083.htmlThird Party Advisory
- http://www.openwall.com/lists/oss-security/2013/06/13/3Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/60545Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.