cbcvebase.
CVE-2013-2014
published 2014-06-02

CVE-2013-2014: OpenStack Identity (Keystone) before 2013.1 allows remote attackers to cause a denial of service (memory consumption and crash) via multiple long requests.

PriorityP422medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
3.24%
86.9th percentile
OpenStack Identity (Keystone) before 2013.1 allows remote attackers to cause a denial of service (memory consumption and crash) via multiple long requests.

Affected

13 ranges
VendorProductVersion rangeFixed in
debiankeystone< keystone 2013.1.1-2 (bookworm)keystone 2013.1.1-2 (bookworm)
eglibceglibc>= 0 < 2.19-0ubuntu6.62.19-0ubuntu6.6
fedoraprojectfedora
jenkinscertain_pages_in_monitoring_plugin
jenkinsjenkins_core
jenkinsmonitoring_plugin
jenkinsuser_of_monitoring_plugin
openstackkeystone>= 0 < 2013.1.1-22013.1.1-2
openstackkeystone>= 0 < 2013.1.1-22013.1.1-2
openstackkeystone>= 0 < 2013.1.1-22013.1.1-2
openstackkeystone>= 0 < 2013.1.1-22013.1.1-2
openstackkeystone>= 0 < 8.0.0a08.0.0a0
openstackkeystone>= 2013 < 2013.12013.1

CVSS provenance

nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_redhat7.2HIGH
vendor_debian5.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.