CVE-2013-0270
published 2013-04-12CVE-2013-0270: A flaw was found in OpenStack Keystone. A remote attacker could exploit this vulnerability by sending a large HTTP request, specifically by providing a long…
PriorityP433medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
3.07%
86.1th percentile
A flaw was found in OpenStack Keystone. A remote attacker could exploit this vulnerability by sending a large HTTP request, specifically by providing a long tenant name when requesting a token. This could lead to a denial of service, consuming excessive CPU and memory resources on the affected system.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | keystone | < keystone 2013.1.1-2 (bookworm) | keystone 2013.1.1-2 (bookworm) |
| openstack | keystone | — | — |
| openstack | keystone | >= 0 < 2013.1.1-2 | 2013.1.1-2 |
| openstack | keystone | >= 0 < 2013.1.1-2 | 2013.1.1-2 |
| openstack | keystone | >= 0 < 2013.1.1-2 | 2013.1.1-2 |
| openstack | keystone | >= 0 < 2013.1.1-2 | 2013.1.1-2 |
| openstack | keystone | >= 0 < 8.0.0a0 | 8.0.0a0 |
| openstack | keystone | 2012.1 – 2012.1.3 | — |
| openstack | keystone | 2012.2 – 2012.2.4 | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
OpenStack Keystone Denial of Service vulnerability via a large HTTP request
ghsa·2022-05-05
CVE-2013-0270 [MEDIUM] CWE-119 OpenStack Keystone Denial of Service vulnerability via a large HTTP request
OpenStack Keystone Denial of Service vulnerability via a large HTTP request
OpenStack Keystone Grizzly before 2013.1, Folsom, and possibly earlier allows remote attackers to cause a denial of service (CPU and memory consumption) via a large HTTP request, as demonstrated by a long tenant_name when requesting a token.
OSV
OpenStack Keystone Denial of Service vulnerability via a large HTTP request
osv·2022-05-05
CVE-2013-0270 [MEDIUM] OpenStack Keystone Denial of Service vulnerability via a large HTTP request
OpenStack Keystone Denial of Service vulnerability via a large HTTP request
OpenStack Keystone Grizzly before 2013.1, Folsom, and possibly earlier allows remote attackers to cause a denial of service (CPU and memory consumption) via a large HTTP request, as demonstrated by a long tenant_name when requesting a token.
OSV
CVE-2013-0270: A flaw was found in OpenStack Keystone
osv·2013-04-12·CVSS 6.5
CVE-2013-0270 [MEDIUM] CVE-2013-0270: A flaw was found in OpenStack Keystone
A flaw was found in OpenStack Keystone. A remote attacker could exploit this vulnerability by sending a large HTTP request, specifically by providing a long tenant name when requesting a token. This could lead to a denial of service, consuming excessive CPU and memory resources on the affected system.
Red Hat
CVE-2013-0270: A flaw was found in OpenStack Keystone
vendor_redhat·2013-04-12·CVSS 6.5
CVE-2013-0270 [MEDIUM] CWE-1284 CVE-2013-0270: A flaw was found in OpenStack Keystone
A flaw was found in OpenStack Keystone. A remote attacker could exploit this vulnerability by sending a large HTTP request, specifically by providing a long tenant name when requesting a token. This could lead to a denial of service, consuming excessive CPU and memory resources on the affected system.
A flaw was found in OpenStack Keystone. A remote attacker could exploit this vulnerability by sending a large HTTP request, specifically by providing a long tenant name when requesting a token. This could lead to a denial of service, consuming excessive CPU and memory resources on the affected system.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applic
Debian
CVE-2013-0270: keystone - A flaw was found in OpenStack Keystone. A remote attacker could exploit this vul...
vendor_debian·2013·CVSS 6.5
CVE-2013-0270 [MEDIUM] CVE-2013-0270: keystone - A flaw was found in OpenStack Keystone. A remote attacker could exploit this vul...
A flaw was found in OpenStack Keystone. A remote attacker could exploit this vulnerability by sending a large HTTP request, specifically by providing a long tenant name when requesting a token. This could lead to a denial of service, consuming excessive CPU and memory resources on the affected system.
Scope: local
bookworm: resolved (fixed in 2013.1.1-2)
bullseye: resolved (fixed in 2013.1.1-2)
forky: resolved (fixed in 2013.1.1-2)
sid: resolved (fixed in 2013.1.1-2)
trixie: resolved (fixed in 2013.1.1-2)
No detection rules found.
No public exploits indexed.
http://rhn.redhat.com/errata/RHSA-2013-0708.htmlhttps://access.redhat.com/security/cve/CVE-2013-0270https://bugs.launchpad.net/keystone/+bug/1099025https://bugzilla.redhat.com/show_bug.cgi?id=909012https://github.com/openstack/keystone/commit/7691276b869a86c2b75631d5bede9f61e030d9d8https://github.com/openstack/keystone/commit/82c87e5638ebaf9f166a9b07a0155291276d6fdchttps://launchpad.net/keystone/grizzly/2013.1http://rhn.redhat.com/errata/RHSA-2013-0708.htmlhttps://bugs.launchpad.net/keystone/+bug/1099025https://bugzilla.redhat.com/show_bug.cgi?id=909012https://github.com/openstack/keystone/commit/7691276b869a86c2b75631d5bede9f61e030d9d8https://github.com/openstack/keystone/commit/82c87e5638ebaf9f166a9b07a0155291276d6fdchttps://launchpad.net/keystone/grizzly/2013.1
2013-04-12
Published