Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2013-2255

Опубликовано: 10 июл. 2013
Источник: redhat
CVSS2: 4.3

Описание

HTTPSConnections in OpenStack Keystone 2013, OpenStack Compute 2013.1, and possibly other OpenStack components, fail to validate server-side SSL certificates.

Отчет

The Red Hat Security Response Team has rated this issue as having Moderate security impact in RedHat Enterprise OpenStack Platform 3 however fixing this issue would require a change to default behavior. This issue is not currently planned to be addressed in future updates. This issue did not affect the versions of openstack-keystone or python-keystone client as shipped with RedHat Enterprise OpenStack Platform 4. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenStack Platform 3openstack-keystoneAffected
Red Hat OpenStack Platform 3python-keystoneclientAffected
Red Hat OpenStack Platform 4openstack-keystoneAffected
Red Hat OpenStack Platform 4python-keystoneclientAffected

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=924514openstack-*: Inconsistent and non-validating HTTPS client

4.3 Medium

CVSS2

Связанные уязвимости

CVSS3: 5.9
ubuntu
больше 6 лет назад

HTTPSConnections in OpenStack Keystone 2013, OpenStack Compute 2013.1, and possibly other OpenStack components, fail to validate server-side SSL certificates.

CVSS3: 5.9
nvd
больше 6 лет назад

HTTPSConnections in OpenStack Keystone 2013, OpenStack Compute 2013.1, and possibly other OpenStack components, fail to validate server-side SSL certificates.

CVSS3: 5.9
debian
больше 6 лет назад

HTTPSConnections in OpenStack Keystone 2013, OpenStack Compute 2013.1, ...

CVSS3: 5.9
github
почти 4 года назад

OpenStack Keystone and other components vulnerable to Improper Certificate Validation

4.3 Medium

CVSS2