Lucene search

K
ubuntucveUbuntu.comUB:CVE-2013-2157
HistoryJun 13, 2013 - 12:00 a.m.

CVE-2013-2157

2013-06-1300:00:00
ubuntu.com
ubuntu.com
19

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

0.003 Low

EPSS

Percentile

66.4%

OpenStack Keystone Folsom, Grizzly before 2013.1.3, and Havana, when using
LDAP with Anonymous binding, allows remote attackers to bypass
authentication via an empty password.

Bugs

Notes

Author Note
seth-arnold patches in Message-ID: <[email protected]>
jdstrand 12.04 LTS does not have 0d32a417c811ce37b1b7ea1fbbc0a8376b9b3723 which is required to be exposed to this bug (ie anonymous binds fail without it) If 0d32a417c811ce37b1b7ea1fbbc0a8376b9b3723 is applied then the patch for folsom will work with some light modifications.
OSVersionArchitecturePackageVersionFilename
ubuntu12.10noarchkeystone< 2012.2.4-0ubuntu3.1UNKNOWN
ubuntu13.04noarchkeystone< 1:2013.1.1-0ubuntu2.1UNKNOWN

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

0.003 Low

EPSS

Percentile

66.4%