CVE-2013-2157
published 2013-08-20CVE-2013-2157: OpenStack Keystone Folsom, Grizzly before 2013.1.3, and Havana, when using LDAP with Anonymous binding, allows remote attackers to bypass authentication via an…
PriorityP433medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
3.13%
86.3th percentile
OpenStack Keystone Folsom, Grizzly before 2013.1.3, and Havana, when using LDAP with Anonymous binding, allows remote attackers to bypass authentication via an empty password.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | keystone | < keystone 2013.1.2-1 (bookworm) | keystone 2013.1.2-1 (bookworm) |
| openstack | keystone | >= 0 < 2013.1.2-1 | 2013.1.2-1 |
| openstack | keystone | >= 0 < 2013.1.2-1 | 2013.1.2-1 |
| openstack | keystone | >= 0 < 2013.1.2-1 | 2013.1.2-1 |
| openstack | keystone | >= 0 < 2013.1.2-1 | 2013.1.2-1 |
| openstack | keystone | 2012.2 – 2012.2.4 | — |
| openstack | keystone | >= 2013.1 < 2013.1.3 | 2013.1.3 |
| openstack | keystone | 2013.2 – 2013.2.4 | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
vendor_ubuntu5.5MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-w396-2gg4-mxgv: OpenStack Keystone Folsom, Grizzly before 2013
ghsa_unreviewed·2022-05-14
CVE-2013-2157 [MEDIUM] CWE-287 GHSA-w396-2gg4-mxgv: OpenStack Keystone Folsom, Grizzly before 2013
OpenStack Keystone Folsom, Grizzly before 2013.1.3, and Havana, when using LDAP with Anonymous binding, allows remote attackers to bypass authentication via an empty password.
OSV
CVE-2013-2157: OpenStack Keystone Folsom, Grizzly before 2013
osv·2013-08-20·CVSS 4.3
CVE-2013-2157 [MEDIUM] CVE-2013-2157: OpenStack Keystone Folsom, Grizzly before 2013
OpenStack Keystone Folsom, Grizzly before 2013.1.3, and Havana, when using LDAP with Anonymous binding, allows remote attackers to bypass authentication via an empty password.
Ubuntu
OpenStack Keystone vulnerabilities
vendor_ubuntu·2013-06-14·CVSS 5.5
CVE-2013-2104 [MEDIUM] OpenStack Keystone vulnerabilities
Title: OpenStack Keystone vulnerabilities
Summary: Keystone did not always properly verify expired PKI tokens or properly
authenticate users.
Eoghan Glynn and Alex Meade discovered that Keystone did not properly
perform expiry checks for the PKI tokens used in Keystone. If Keystone were
setup to use PKI tokens, a previously authenticated user could continue to
use a PKI token for longer than intended. This issue only affected Ubuntu
12.10 which does not use PKI tokens by default. (CVE-2013-2104)
Jose Castro Leon discovered that Keystone did not properly authenticate
users when using the LDAP backend. An attacker could obtain valid tokens
and impersonate other users by supplying an empty password. By default,
Ubuntu does not use the LDAP backend. (CVE-2013-2157)
Instructions: In general
Red Hat
openstack-keystone: Authentication bypass when using LDAP backend
vendor_redhat·2013-06-13·CVSS 4.3
CVE-2013-2157 [MEDIUM] openstack-keystone: Authentication bypass when using LDAP backend
openstack-keystone: Authentication bypass when using LDAP backend
OpenStack Keystone Folsom, Grizzly before 2013.1.3, and Havana, when using LDAP with Anonymous binding, allows remote attackers to bypass authentication via an empty password.
Debian
CVE-2013-2157: keystone - OpenStack Keystone Folsom, Grizzly before 2013.1.3, and Havana, when using LDAP ...
vendor_debian·2013·CVSS 4.3
CVE-2013-2157 [MEDIUM] CVE-2013-2157: keystone - OpenStack Keystone Folsom, Grizzly before 2013.1.3, and Havana, when using LDAP ...
OpenStack Keystone Folsom, Grizzly before 2013.1.3, and Havana, when using LDAP with Anonymous binding, allows remote attackers to bypass authentication via an empty password.
Scope: local
bookworm: resolved (fixed in 2013.1.2-1)
bullseye: resolved (fixed in 2013.1.2-1)
forky: resolved (fixed in 2013.1.2-1)
sid: resolved (fixed in 2013.1.2-1)
trixie: resolved (fixed in 2013.1.2-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-2157 openstack-keystone: Authentication bypass when using LDAP backend [epel-6]
bugzilla·2013-06-17·CVSS 4.3
CVE-2013-2157 [MEDIUM] CVE-2013-2157 openstack-keystone: Authentication bypass when using LDAP backend [epel-6]
CVE-2013-2157 openstack-keystone: Authentication bypass when using LDAP backend [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
epel-6 trac
Bugzilla
CVE-2013-2157 openstack-keystone: Authentication bypass when using LDAP backend [fedora-all]
bugzilla·2013-06-17·CVSS 4.3
CVE-2013-2157 [MEDIUM] CVE-2013-2157 openstack-keystone: Authentication bypass when using LDAP backend [fedora-all]
CVE-2013-2157 openstack-keystone: Authentication bypass when using LDAP backend [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note:
Bugzilla
CVE-2013-2157 openstack-keystone: Authentication bypass when using LDAP backend
bugzilla·2013-06-07·CVSS 4.3
CVE-2013-2157 [MEDIUM] CVE-2013-2157 openstack-keystone: Authentication bypass when using LDAP backend
CVE-2013-2157 openstack-keystone: Authentication bypass when using LDAP backend
A security flaw was found in the way Keystone, a Python implementation of the OpenStack identity service API, performed user authentication when the LDAP backend was used (previously user-provided empty LDAP password resulted into an anonymous LDAP bind to be performed, resulting into successful user authentication). A remote attacker could use this flaw to obtain unauthorized access to the OpenStack functionality (user account impersonation, retrieval of valid authentication tokens).
Note: This issue solely affects only Keystone configurations using the LDAP authentication backend.
Acknowledgements:
Red Hat would like to thank Thierry Carrez of OpenStack upstream for reporting this issue. Upstream acknowle
http://rhn.redhat.com/errata/RHSA-2013-0994.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1083.htmlhttp://www.openwall.com/lists/oss-security/2013/06/13/3http://www.securityfocus.com/bid/60545http://rhn.redhat.com/errata/RHSA-2013-0994.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1083.htmlhttp://www.openwall.com/lists/oss-security/2013/06/13/3http://www.securityfocus.com/bid/60545
2013-08-20
Published