CVE-2013-0270

Severity CVSS v4.0:
Pending analysis
Type:
CWE-119 Buffer Errors
Publication date:
12/04/2013
Last modified:
11/04/2025

Description

OpenStack Keystone Grizzly before 2013.1, Folsom, and possibly earlier allows remote attackers to cause a denial of service (CPU and memory consumption) via a large HTTP request, as demonstrated by a long tenant_name when requesting a token.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:openstack:keystone:*:*:*:*:*:*:*:* 2012.1 (including) 2012.1.3 (including)
cpe:2.3:a:openstack:keystone:*:*:*:*:*:*:*:* 2012.2 (including) 2012.2.4 (including)
cpe:2.3:a:openstack:keystone:2013.1:milestone1:*:*:*:*:*:*
cpe:2.3:a:openstack:keystone:2013.1:milestone2:*:*:*:*:*:*
cpe:2.3:a:openstack:keystone:2013.1:milestone3:*:*:*:*:*:*