CVE-2013-2255: Medium severity Openstack Compute vulnerability
HTTPSConnections in OpenStack Keystone 2013, OpenStack Compute 2013.1, and possibly other OpenStack components, fail to validate server-side SSL certificates.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2013-2255.
What is the severity level of CVE-2013-2255?
The severity level of CVE-2013-2255 is medium with a severity value of 5.9.
Which OpenStack components are affected by CVE-2013-2255?
CVE-2013-2255 affects OpenStack Keystone 2013, OpenStack Compute 2013.1, and possibly other OpenStack components.
How do I fix this vulnerability in Keystone and Swift packages on Debian?
To fix this vulnerability in Keystone, update to version 2:14.2.0-0+deb10u1, 2:18.0.0-3+deb11u1, 2:22.0.0-2, or 2:24.0.0-1. For Swift, update to version 2.19.1-1, 2.19.1-1+deb10u1, 2.26.0-10+deb11u1, 2.30.0-4, or 2.32.0-2.
Where can I find more information about CVE-2013-2255?
More information about CVE-2013-2255 can be found at the following references: [Access Red Hat](https://access.redhat.com/security/cve/cve-2013-2255), [Launchpad](https://bugs.launchpad.net/ossn/+bug/1188189), and [Bugzilla Red Hat](https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-2255).