CVE-2013-0282
Last modified
CVE-2013-0282 is a vulnerability of currently unknown severity. OpenStack Keystone Grizzly before 2013.1, Folsom 2012.1.3 and earlier, and Essex does not properly check if the (1) user, (2) tenant, or (3) domain is enabled when using EC2-style authentication, which allows context-dependent attackers to bypass access restrictions.. EPSS estimates a 1.75% chance of exploitation in the next 30 days.
Description
OpenStack Keystone Grizzly before 2013.1, Folsom 2012.1.3 and earlier, and Essex does not properly check if the (1) user, (2) tenant, or (3) domain is enabled when using EC2-style authentication, which allows context-dependent attackers to bypass access restrictions.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Openstack | Keystone | >= 2012.1, <= 2012.1.3 | — |
| Openstack | Keystone | >= 2012.2, <= 2012.2.4 | — |
| Openstack | Keystone | 2013.1 | Milestone1 |
References
- http://www.openwall.com/lists/oss-security/2013/02/19/3Third Party Advisory
- https://bugs.launchpad.net/keystone/+bug/1121494Third Party Advisory
- https://launchpad.net/keystone/+milestone/2012.2.4Third Party Advisory
- https://launchpad.net/keystone/grizzly/2013.1Third Party Advisory
- https://review.openstack.org/#/c/22319/Vendor Advisory
- https://review.openstack.org/#/c/22320/Vendor Advisory
- https://review.openstack.org/#/c/22321/Vendor Advisory
- http://www.openwall.com/lists/oss-security/2013/02/19/3Third Party Advisory
- https://bugs.launchpad.net/keystone/+bug/1121494Third Party Advisory
- https://launchpad.net/keystone/+milestone/2012.2.4Third Party Advisory
- https://launchpad.net/keystone/grizzly/2013.1Third Party Advisory
- https://review.openstack.org/#/c/22319/Vendor Advisory
- https://review.openstack.org/#/c/22320/Vendor Advisory
- https://review.openstack.org/#/c/22321/Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2013-0282?
How severe is CVE-2013-0282?
How do I fix CVE-2013-0282?
Are you affected by CVE-2013-0282?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
