Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 4

Количество 4

ubuntu логотип

CVE-2021-38155

около 5 лет назад

OpenStack Keystone 10.x through 16.x before 16.0.2, 17.x before 17.0.1, 18.x before 18.0.1, and 19.x before 19.0.1 allows information disclosure during account locking (related to PCI DSS features). By guessing the name of an account and failing to authenticate multiple times, any unauthenticated actor could both confirm the account exists and obtain that account's corresponding UUID, which might be leveraged for other unrelated attacks. All deployments enabling security_compliance.lockout_failure_attempts are affected.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2021-38155

около 5 лет назад

OpenStack Keystone 10.x through 16.x before 16.0.2, 17.x before 17.0.1, 18.x before 18.0.1, and 19.x before 19.0.1 allows information disclosure during account locking (related to PCI DSS features). By guessing the name of an account and failing to authenticate multiple times, any unauthenticated actor could both confirm the account exists and obtain that account's corresponding UUID, which might be leveraged for other unrelated attacks. All deployments enabling security_compliance.lockout_failure_attempts are affected.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2021-38155

около 5 лет назад

OpenStack Keystone 10.x through 16.x before 16.0.2, 17.x before 17.0.1 ...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4225-97pr-rr52

больше 4 лет назад

OpenStack Keystone allows information disclosure during account locking

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2021-38155

OpenStack Keystone 10.x through 16.x before 16.0.2, 17.x before 17.0.1, 18.x before 18.0.1, and 19.x before 19.0.1 allows information disclosure during account locking (related to PCI DSS features). By guessing the name of an account and failing to authenticate multiple times, any unauthenticated actor could both confirm the account exists and obtain that account's corresponding UUID, which might be leveraged for other unrelated attacks. All deployments enabling security_compliance.lockout_failure_attempts are affected.

CVSS3: 7.5
2%
Низкий
около 5 лет назад
nvd логотип
CVE-2021-38155

OpenStack Keystone 10.x through 16.x before 16.0.2, 17.x before 17.0.1, 18.x before 18.0.1, and 19.x before 19.0.1 allows information disclosure during account locking (related to PCI DSS features). By guessing the name of an account and failing to authenticate multiple times, any unauthenticated actor could both confirm the account exists and obtain that account's corresponding UUID, which might be leveraged for other unrelated attacks. All deployments enabling security_compliance.lockout_failure_attempts are affected.

CVSS3: 7.5
2%
Низкий
около 5 лет назад
debian логотип
CVE-2021-38155

OpenStack Keystone 10.x through 16.x before 16.0.2, 17.x before 17.0.1 ...

CVSS3: 7.5
2%
Низкий
около 5 лет назад
github логотип
GHSA-4225-97pr-rr52

OpenStack Keystone allows information disclosure during account locking

CVSS3: 7.5
2%
Низкий
больше 4 лет назад

Уязвимостей на страницу