Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-3563

Опубликовано: 17 фев. 2021
Источник: redhat
CVSS3: 7.4
EPSS Низкий

Описание

A flaw was found in openstack-keystone. Only the first 72 characters of an application secret are verified allowing attackers bypass some password complexity which administrators may be counting on. The highest threat from this vulnerability is to data confidentiality and integrity.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenStack Platform 10 (Newton)openstack-keystoneOut of support scope
Red Hat OpenStack Platform 13 (Queens)openstack-keystoneOut of support scope
Red Hat OpenStack Platform 16.1openstack-keystoneAffected
Red Hat OpenStack Platform 16.2openstack-keystoneWill not fix
Red Hat OpenStack Platform 17.0openstack-keystoneOut of support scope

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-863
https://bugzilla.redhat.com/show_bug.cgi?id=1962908Keystone: Verification of application credentials is silently length-limited

EPSS

Процентиль: 16%
0.00053
Низкий

7.4 High

CVSS3

Связанные уязвимости

CVSS3: 7.4
ubuntu
больше 3 лет назад

A flaw was found in openstack-keystone. Only the first 72 characters of an application secret are verified allowing attackers bypass some password complexity which administrators may be counting on. The highest threat from this vulnerability is to data confidentiality and integrity.

CVSS3: 7.4
nvd
больше 3 лет назад

A flaw was found in openstack-keystone. Only the first 72 characters of an application secret are verified allowing attackers bypass some password complexity which administrators may be counting on. The highest threat from this vulnerability is to data confidentiality and integrity.

CVSS3: 7.4
debian
больше 3 лет назад

A flaw was found in openstack-keystone. Only the first 72 characters o ...

CVSS3: 9.1
github
больше 3 лет назад

Openstack Keystone Incorrect Authorization vulnerability

EPSS

Процентиль: 16%
0.00053
Низкий

7.4 High

CVSS3