First published: Tue Aug 20 2013(Updated: )
OpenStack Keystone Folsom, Grizzly before 2013.1.3, and Havana, when using LDAP with Anonymous binding, allows remote attackers to bypass authentication via an empty password.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
OpenStack Keystone | >=2012.2<=2012.2.4 | |
OpenStack Keystone | >=2013.1<2013.1.3 | |
OpenStack Keystone | >=2013.2<=2013.2.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.