CVE-2013-0247
published 2013-02-24CVE-2013-0247: OpenStack Keystone Essex 2012.1.3 and earlier, Folsom 2012.2.3 and earlier, and Grizzly grizzly-2 and earlier allows remote attackers to cause a denial of…
PriorityP422medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
3.24%
86.9th percentile
OpenStack Keystone Essex 2012.1.3 and earlier, Folsom 2012.2.3 and earlier, and Grizzly grizzly-2 and earlier allows remote attackers to cause a denial of service (disk consumption) via many invalid token requests that trigger excessive generation of log entries.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | keystone | < keystone 2012.1.1-12 (bookworm) | keystone 2012.1.1-12 (bookworm) |
| openstack | keystone | >= 0 < 2012.1.1-12 | 2012.1.1-12 |
| openstack | keystone | >= 0 < 2012.1.1-12 | 2012.1.1-12 |
| openstack | keystone | >= 0 < 2012.1.1-12 | 2012.1.1-12 |
| openstack | keystone | >= 0 < 2012.1.1-12 | 2012.1.1-12 |
| openstack | keystone | 2012.1 – 2012.1.3 | — |
| openstack | keystone | 2012.2 – 2012.2.3 | — |
| openstack | keystone | 2013.1 – 2013.1.2 | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fqpq-8vh2-cxwp: OpenStack Keystone Essex 2012
ghsa_unreviewed·2022-05-05
CVE-2013-0247 [MEDIUM] GHSA-fqpq-8vh2-cxwp: OpenStack Keystone Essex 2012
OpenStack Keystone Essex 2012.1.3 and earlier, Folsom 2012.2.3 and earlier, and Grizzly grizzly-2 and earlier allows remote attackers to cause a denial of service (disk consumption) via many invalid token requests that trigger excessive generation of log entries.
OSV
CVE-2013-0247: OpenStack Keystone Essex 2012
osv·2013-02-24·CVSS 5.0
CVE-2013-0247 [MEDIUM] CVE-2013-0247: OpenStack Keystone Essex 2012
OpenStack Keystone Essex 2012.1.3 and earlier, Folsom 2012.2.3 and earlier, and Grizzly grizzly-2 and earlier allows remote attackers to cause a denial of service (disk consumption) via many invalid token requests that trigger excessive generation of log entries.
Ubuntu
OpenStack Keystone vulnerability
vendor_ubuntu·2013-02-05
CVE-2013-0247 OpenStack Keystone vulnerability
Title: OpenStack Keystone vulnerability
Summary: Keystone could be made to fill server disks with error messages.
Dan Prince discovered that Keystone did not properly perform input
validation when handling certain error conditions. An unauthenticated user
could exploit this to cause a denial of service in Keystone API servers via
disk space exhaustion.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
Keystone: denial of service through invalid token requests
vendor_redhat·2013-02-05·CVSS 5.0
CVE-2013-0247 [MEDIUM] Keystone: denial of service through invalid token requests
Keystone: denial of service through invalid token requests
OpenStack Keystone Essex 2012.1.3 and earlier, Folsom 2012.2.3 and earlier, and Grizzly grizzly-2 and earlier allows remote attackers to cause a denial of service (disk consumption) via many invalid token requests that trigger excessive generation of log entries.
Debian
CVE-2013-0247: keystone - OpenStack Keystone Essex 2012.1.3 and earlier, Folsom 2012.2.3 and earlier, and ...
vendor_debian·2013·CVSS 5.0
CVE-2013-0247 [MEDIUM] CVE-2013-0247: keystone - OpenStack Keystone Essex 2012.1.3 and earlier, Folsom 2012.2.3 and earlier, and ...
OpenStack Keystone Essex 2012.1.3 and earlier, Folsom 2012.2.3 and earlier, and Grizzly grizzly-2 and earlier allows remote attackers to cause a denial of service (disk consumption) via many invalid token requests that trigger excessive generation of log entries.
Scope: local
bookworm: resolved (fixed in 2012.1.1-12)
bullseye: resolved (fixed in 2012.1.1-12)
forky: resolved (fixed in 2012.1.1-12)
sid: resolved (fixed in 2012.1.1-12)
trixie: resolved (fixed in 2012.1.1-12)
No detection rules found.
No public exploits indexed.
http://lists.fedoraproject.org/pipermail/package-announce/2013-February/098906.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0253.htmlhttp://www.securityfocus.com/bid/57747http://www.ubuntu.com/usn/USN-1715-1https://bugs.launchpad.net/keystone/+bug/1098307https://bugzilla.redhat.com/show_bug.cgi?id=906171http://lists.fedoraproject.org/pipermail/package-announce/2013-February/098906.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0253.htmlhttp://www.securityfocus.com/bid/57747http://www.ubuntu.com/usn/USN-1715-1https://bugs.launchpad.net/keystone/+bug/1098307https://bugzilla.redhat.com/show_bug.cgi?id=906171
2013-02-24
Published