CVE-2013-0247: Medium severity keystone vulnerability
OpenStack Keystone Essex 2012.1.3 and earlier, Folsom 2012.2.3 and earlier, and Grizzly grizzly-2 and earlier allows remote attackers to cause a denial of service (disk consumption) via many invalid token requests that trigger excessive generation of log entries.
Other sources
Thierry Carrez (thierry) of the OpenStack Project reports:
Title: Keystone denial of service through invalid token requests Reporter: Dan Prince (Red Hat) Products: Keystone Affects: All versions
Description: Dan Prince of Red Hat reported a vulnerability in token creation error handling in Keystone. By requesting lots of invalid tokens, an unauthenticated user may fill up logs on Keystone API servers disks, potentially resulting in a denial of service attack against Keystone.
Proposed patches: See attached patches for current development tree (Grizzly) and the Folsom and Essex series. Unless a flaw is discovered in them, these proposed patches will be merged to Keystone master, stable/folsom and stable/essex branches on the public disclosure date.
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2013-0247?
CVE-2013-0247 is classified as a denial of service vulnerability.
How does CVE-2013-0247 affect OpenStack Keystone?
CVE-2013-0247 allows remote attackers to cause disk consumption by creating excessive log entries through invalid token requests.
Which versions of OpenStack Keystone are affected by CVE-2013-0247?
CVE-2013-0247 affects OpenStack Keystone versions 2012.1.3 and earlier, 2012.2.3 and earlier, and 2013.1.2 and earlier.
How can I mitigate the impact of CVE-2013-0247?
Mitigation for CVE-2013-0247 can involve limiting the rate of token requests and controlling log generation.
Is there a patch available for CVE-2013-0247?
You should upgrade to a version of OpenStack Keystone that is later than 2013.1.2 to address CVE-2013-0247.