First published: Tue Aug 20 2013(Updated: )
OpenStack Keystone Folsom, Grizzly before 2013.1.3, and Havana, when using LDAP with Anonymous binding, allows remote attackers to bypass authentication via an empty password.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
OpenStack keystonemiddleware | >=2012.2<=2012.2.4 | |
OpenStack keystonemiddleware | >=2013.1<2013.1.3 | |
OpenStack keystonemiddleware | >=2013.2<=2013.2.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-2157 has a moderate severity level as it allows attackers to bypass authentication.
To fix CVE-2013-2157, upgrade OpenStack Keystone to version 2013.1.3 or later.
CVE-2013-2157 affects OpenStack Keystone versions from 2012.2 up to, but not including, 2013.1.3.
CVE-2013-2157 enables remote attackers to bypass authentication using an empty password.
Yes, CVE-2013-2157 is specifically related to LDAP configurations using Anonymous binding.