CVE-2013-0282
published 2013-04-12CVE-2013-0282: OpenStack Keystone Grizzly before 2013.1, Folsom 2012.1.3 and earlier, and Essex does not properly check if the (1) user, (2) tenant, or (3) domain is enabled…
PriorityP427medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
1.75%
75.3th percentile
OpenStack Keystone Grizzly before 2013.1, Folsom 2012.1.3 and earlier, and Essex does not properly check if the (1) user, (2) tenant, or (3) domain is enabled when using EC2-style authentication, which allows context-dependent attackers to bypass access restrictions.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | keystone | < keystone 2012.1.1-13 (bookworm) | keystone 2012.1.1-13 (bookworm) |
| openstack | keystone | — | — |
| openstack | keystone | >= 0 < 2012.1.1-13 | 2012.1.1-13 |
| openstack | keystone | >= 0 < 2012.1.1-13 | 2012.1.1-13 |
| openstack | keystone | >= 0 < 2012.1.1-13 | 2012.1.1-13 |
| openstack | keystone | >= 0 < 2012.1.1-13 | 2012.1.1-13 |
| openstack | keystone | >= 0 < 8.0.0a0 | 8.0.0a0 |
| openstack | keystone | 2012.1 – 2012.1.3 | — |
| openstack | keystone | 2012.2 – 2012.2.4 | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
OpenStack Keystone vulnerabilities
vendor_ubuntu·2013-02-20·CVSS 5.0
CVE-2013-0282 [MEDIUM] OpenStack Keystone vulnerabilities
Title: OpenStack Keystone vulnerabilities
Summary: Keystone could be made to crash or expose sensitive information over the
network.
Nathanael Burton discovered that Keystone did not properly verify disabled
users. An authenticated but disabled user would continue to have access
rights that were removed. (CVE-2013-0282)
Jonathan Murray discovered that Keystone would allow XML entity processing.
A remote unauthenticated attacker could exploit this to cause a denial of
service via resource exhaustion. Authenticated users could also use this to
view arbitrary files on the Keystone server. (CVE-2013-1664, CVE-2013-1665)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
Keystone: EC2-style authentication accepts disabled user/tenants
vendor_redhat·2013-02-19·CVSS 5.0
CVE-2013-0282 [MEDIUM] Keystone: EC2-style authentication accepts disabled user/tenants
Keystone: EC2-style authentication accepts disabled user/tenants
OpenStack Keystone Grizzly before 2013.1, Folsom 2012.1.3 and earlier, and Essex does not properly check if the (1) user, (2) tenant, or (3) domain is enabled when using EC2-style authentication, which allows context-dependent attackers to bypass access restrictions.
Debian
CVE-2013-0282: keystone - OpenStack Keystone Grizzly before 2013.1, Folsom 2012.1.3 and earlier, and Essex...
vendor_debian·2013·CVSS 5.0
CVE-2013-0282 [MEDIUM] CVE-2013-0282: keystone - OpenStack Keystone Grizzly before 2013.1, Folsom 2012.1.3 and earlier, and Essex...
OpenStack Keystone Grizzly before 2013.1, Folsom 2012.1.3 and earlier, and Essex does not properly check if the (1) user, (2) tenant, or (3) domain is enabled when using EC2-style authentication, which allows context-dependent attackers to bypass access restrictions.
Scope: local
bookworm: resolved (fixed in 2012.1.1-13)
bullseye: resolved (fixed in 2012.1.1-13)
forky: resolved (fixed in 2012.1.1-13)
sid: resolved (fixed in 2012.1.1-13)
trixie: resolved (fixed in 2012.1.1-13)
OSV
OpenStack Keystone allows context-dependent attackers to bypass access restrictions
osv·2022-05-05
CVE-2013-0282 [MEDIUM] OpenStack Keystone allows context-dependent attackers to bypass access restrictions
OpenStack Keystone allows context-dependent attackers to bypass access restrictions
OpenStack Keystone Grizzly before 2013.1, Folsom 2012.1.3 and earlier, and Essex does not properly check if the (1) user, (2) tenant, or (3) domain is enabled when using EC2-style authentication, which allows context-dependent attackers to bypass access restrictions.
GHSA
OpenStack Keystone allows context-dependent attackers to bypass access restrictions
ghsa·2022-05-05
CVE-2013-0282 [MEDIUM] CWE-287 OpenStack Keystone allows context-dependent attackers to bypass access restrictions
OpenStack Keystone allows context-dependent attackers to bypass access restrictions
OpenStack Keystone Grizzly before 2013.1, Folsom 2012.1.3 and earlier, and Essex does not properly check if the (1) user, (2) tenant, or (3) domain is enabled when using EC2-style authentication, which allows context-dependent attackers to bypass access restrictions.
OSV
CVE-2013-0282: OpenStack Keystone Grizzly before 2013
osv·2013-04-12·CVSS 5.0
CVE-2013-0282 [MEDIUM] CVE-2013-0282: OpenStack Keystone Grizzly before 2013
OpenStack Keystone Grizzly before 2013.1, Folsom 2012.1.3 and earlier, and Essex does not properly check if the (1) user, (2) tenant, or (3) domain is enabled when using EC2-style authentication, which allows context-dependent attackers to bypass access restrictions.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-0282 OpenStack Keystone: EC2-style authentication accepts disabled user/tenants [epel-6]
bugzilla·2013-02-19·CVSS 5.0
CVE-2013-0282 [MEDIUM] CVE-2013-0282 OpenStack Keystone: EC2-style authentication accepts disabled user/tenants [epel-6]
CVE-2013-0282 OpenStack Keystone: EC2-style authentication accepts disabled user/tenants [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
ep
Bugzilla
CVE-2013-0282 OpenStack Keystone: EC2-style authentication accepts disabled user/tenants [fedora-all]
bugzilla·2013-02-19·CVSS 5.0
CVE-2013-0282 [MEDIUM] CVE-2013-0282 OpenStack Keystone: EC2-style authentication accepts disabled user/tenants [fedora-all]
CVE-2013-0282 OpenStack Keystone: EC2-style authentication accepts disabled user/tenants [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Ple
Bugzilla
CVE-2013-0282 OpenStack Keystone: EC2-style authentication accepts disabled user/tenants
bugzilla·2013-02-13·CVSS 5.0
CVE-2013-0282 [MEDIUM] CVE-2013-0282 OpenStack Keystone: EC2-style authentication accepts disabled user/tenants
CVE-2013-0282 OpenStack Keystone: EC2-style authentication accepts disabled user/tenants
Russell Bryant ([email protected]) reports:
Title: Keystone EC2-style authentication accepts disabled user/tenants
Reporter: Nathanael Burton (National Security Agency)
Products: Keystone
Affects: All versions
Description:
Nathanael Burton reported a vulnerability in EC2-style authentication
in Keystone. Keystone fails to check whether a user, tenant, or domain
is enabled before authenticating a user using the EC2 api.
Authenticated, but disabled users (or authenticated users in disabled
tenants or domains) could therefore retain access rights that were
thought removed. Only setups enabling EC2-style authentication are
affected. To disable EC2-style authentication to work around the
issue, remove t
http://www.openwall.com/lists/oss-security/2013/02/19/3https://bugs.launchpad.net/keystone/+bug/1121494https://launchpad.net/keystone/+milestone/2012.2.4https://launchpad.net/keystone/grizzly/2013.1https://review.openstack.org/#/c/22319/https://review.openstack.org/#/c/22320/https://review.openstack.org/#/c/22321/http://www.openwall.com/lists/oss-security/2013/02/19/3https://bugs.launchpad.net/keystone/+bug/1121494https://launchpad.net/keystone/+milestone/2012.2.4https://launchpad.net/keystone/grizzly/2013.1https://review.openstack.org/#/c/22319/https://review.openstack.org/#/c/22320/https://review.openstack.org/#/c/22321/
2013-04-12
Published