CVE-2013-2157

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
20/08/2013
Last modified:
11/04/2025

Description

OpenStack Keystone Folsom, Grizzly before 2013.1.3, and Havana, when using LDAP with Anonymous binding, allows remote attackers to bypass authentication via an empty password.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:openstack:keystone:*:*:*:*:*:*:*:* 2012.2 (including) 2012.2.4 (including)
cpe:2.3:a:openstack:keystone:*:*:*:*:*:*:*:* 2013.1 (including) 2013.1.3 (excluding)
cpe:2.3:a:openstack:keystone:*:*:*:*:*:*:*:* 2013.2 (including) 2013.2.4 (including)