First published: Mon Jun 02 2014(Updated: )
OpenStack Identity (Keystone) before 2013.1 allows remote attackers to cause a denial of service (memory consumption and crash) via multiple long requests.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
pip/keystone | <8.0.0a0 | 8.0.0a0 |
OpenStack keystonemiddleware | >=2013<2013.1 | |
Fedora | =19 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-2014 is classified as a denial of service vulnerability due to its potential to cause significant memory consumption and crashes.
To mitigate CVE-2013-2014, upgrade OpenStack Identity (Keystone) to version 8.0.0a0 or later.
CVE-2013-2014 affects Keystone versions before 2013.1.
Yes, CVE-2013-2014 can be exploited remotely by sending multiple long requests to the Keystone service.
CVE-2013-2014 impacts OpenStack Keystone versions prior to 2013.1 and Fedora version 19.