CVE-2013-0270

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
12/04/2013
Last modified:
07/04/2026

Description

A flaw was found in OpenStack Keystone. A remote attacker could exploit this vulnerability by sending a large HTTP request, specifically by providing a long tenant name when requesting a token. This could lead to a denial of service, consuming excessive CPU and memory resources on the affected system.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:openstack:keystone:*:*:*:*:*:*:*:* 2012.1 (including) 2012.1.3 (including)
cpe:2.3:a:openstack:keystone:*:*:*:*:*:*:*:* 2012.2 (including) 2012.2.4 (including)
cpe:2.3:a:openstack:keystone:2013.1:milestone1:*:*:*:*:*:*
cpe:2.3:a:openstack:keystone:2013.1:milestone2:*:*:*:*:*:*
cpe:2.3:a:openstack:keystone:2013.1:milestone3:*:*:*:*:*:*