Описание
OpenStack Keystone Folsom, Grizzly before 2013.1.3, and Havana, when using LDAP with Anonymous binding, allows remote attackers to bypass authentication via an empty password.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat OpenStack Platform 2.1 | openstack-keystone | Affected | ||
| RHOS Essex Release | openstack-keystone | Under investigation | ||
| OpenStack 3 for RHEL 6 | openstack-keystone | Fixed | RHSA-2013:0994 | 27.06.2013 |
| OpenStack Folsom for RHEL 6 | openstack-keystone | Fixed | RHSA-2013:1083 | 16.07.2013 |
Показывать по
Дополнительная информация
Статус:
EPSS
5 Medium
CVSS2
Связанные уязвимости
OpenStack Keystone Folsom, Grizzly before 2013.1.3, and Havana, when using LDAP with Anonymous binding, allows remote attackers to bypass authentication via an empty password.
OpenStack Keystone Folsom, Grizzly before 2013.1.3, and Havana, when using LDAP with Anonymous binding, allows remote attackers to bypass authentication via an empty password.
OpenStack Keystone Folsom, Grizzly before 2013.1.3, and Havana, when u ...
OpenStack Keystone Folsom, Grizzly before 2013.1.3, and Havana, when using LDAP with Anonymous binding, allows remote attackers to bypass authentication via an empty password.
EPSS
5 Medium
CVSS2