Логотип exploitDog
bind:CVE-2021-38155
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-38155

Количество 4

Количество 4

ubuntu логотип

CVE-2021-38155

больше 4 лет назад

OpenStack Keystone 10.x through 16.x before 16.0.2, 17.x before 17.0.1, 18.x before 18.0.1, and 19.x before 19.0.1 allows information disclosure during account locking (related to PCI DSS features). By guessing the name of an account and failing to authenticate multiple times, any unauthenticated actor could both confirm the account exists and obtain that account's corresponding UUID, which might be leveraged for other unrelated attacks. All deployments enabling security_compliance.lockout_failure_attempts are affected.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2021-38155

больше 4 лет назад

OpenStack Keystone 10.x through 16.x before 16.0.2, 17.x before 17.0.1, 18.x before 18.0.1, and 19.x before 19.0.1 allows information disclosure during account locking (related to PCI DSS features). By guessing the name of an account and failing to authenticate multiple times, any unauthenticated actor could both confirm the account exists and obtain that account's corresponding UUID, which might be leveraged for other unrelated attacks. All deployments enabling security_compliance.lockout_failure_attempts are affected.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2021-38155

больше 4 лет назад

OpenStack Keystone 10.x through 16.x before 16.0.2, 17.x before 17.0.1 ...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4225-97pr-rr52

больше 3 лет назад

OpenStack Keystone allows information disclosure during account locking

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2021-38155

OpenStack Keystone 10.x through 16.x before 16.0.2, 17.x before 17.0.1, 18.x before 18.0.1, and 19.x before 19.0.1 allows information disclosure during account locking (related to PCI DSS features). By guessing the name of an account and failing to authenticate multiple times, any unauthenticated actor could both confirm the account exists and obtain that account's corresponding UUID, which might be leveraged for other unrelated attacks. All deployments enabling security_compliance.lockout_failure_attempts are affected.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-38155

OpenStack Keystone 10.x through 16.x before 16.0.2, 17.x before 17.0.1, 18.x before 18.0.1, and 19.x before 19.0.1 allows information disclosure during account locking (related to PCI DSS features). By guessing the name of an account and failing to authenticate multiple times, any unauthenticated actor could both confirm the account exists and obtain that account's corresponding UUID, which might be leveraged for other unrelated attacks. All deployments enabling security_compliance.lockout_failure_attempts are affected.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-38155

OpenStack Keystone 10.x through 16.x before 16.0.2, 17.x before 17.0.1 ...

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-4225-97pr-rr52

OpenStack Keystone allows information disclosure during account locking

CVSS3: 7.5
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу