Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2013-0282

Опубликовано: 19 фев. 2013
Источник: redhat
CVSS2: 4

Описание

OpenStack Keystone Grizzly before 2013.1, Folsom 2012.1.3 and earlier, and Essex does not properly check if the (1) user, (2) tenant, or (3) domain is enabled when using EC2-style authentication, which allows context-dependent attackers to bypass access restrictions.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenStack Platform 2.1openstack-keystoneAffected
RHOS Essex Releaseopenstack-keystoneAffected
OpenStack Folsom for RHEL 6openstack-keystoneFixedRHSA-2013:059605.03.2013

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=910928Keystone: EC2-style authentication accepts disabled user/tenants

4 Medium

CVSS2

Связанные уязвимости

ubuntu
почти 13 лет назад

OpenStack Keystone Grizzly before 2013.1, Folsom 2012.1.3 and earlier, and Essex does not properly check if the (1) user, (2) tenant, or (3) domain is enabled when using EC2-style authentication, which allows context-dependent attackers to bypass access restrictions.

nvd
почти 13 лет назад

OpenStack Keystone Grizzly before 2013.1, Folsom 2012.1.3 and earlier, and Essex does not properly check if the (1) user, (2) tenant, or (3) domain is enabled when using EC2-style authentication, which allows context-dependent attackers to bypass access restrictions.

debian
почти 13 лет назад

OpenStack Keystone Grizzly before 2013.1, Folsom 2012.1.3 and earlier, ...

github
почти 4 года назад

OpenStack Keystone allows context-dependent attackers to bypass access restrictions

4 Medium

CVSS2