CVE-2013-2157: Medium severity keystone vulnerability
Published Aug 20, 2013
·Updated
OpenStack Keystone Folsom, Grizzly before 2013.1.3, and Havana, when using LDAP with Anonymous binding, allows remote attackers to bypass authentication via an empty password.
Affected Software
3 affected components
Openstack Keystone>=2012.2<=2012.2.4
Openstack Keystone>=2013.1<2013.1.3
Openstack Keystone>=2013.2<=2013.2.4
Event History
Aug 20, 2013
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-2157?
CVE-2013-2157 has a moderate severity level as it allows attackers to bypass authentication.
2
How do I fix CVE-2013-2157?
To fix CVE-2013-2157, upgrade OpenStack Keystone to version 2013.1.3 or later.
3
Which versions are affected by CVE-2013-2157?
CVE-2013-2157 affects OpenStack Keystone versions from 2012.2 up to, but not including, 2013.1.3.
4
What type of attack does CVE-2013-2157 enable?
CVE-2013-2157 enables remote attackers to bypass authentication using an empty password.
5
Is CVE-2013-2157 related to LDAP configurations?
Yes, CVE-2013-2157 is specifically related to LDAP configurations using Anonymous binding.