cbcvebase.
CVE-2013-2157
published 2013-08-20

CVE-2013-2157: OpenStack Keystone Folsom, Grizzly before 2013.1.3, and Havana, when using LDAP with Anonymous binding, allows remote attackers to bypass authentication via an…

PriorityP433medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
3.13%
86.3th percentile
OpenStack Keystone Folsom, Grizzly before 2013.1.3, and Havana, when using LDAP with Anonymous binding, allows remote attackers to bypass authentication via an empty password.

Affected

8 ranges
VendorProductVersion rangeFixed in
debiankeystone< keystone 2013.1.2-1 (bookworm)keystone 2013.1.2-1 (bookworm)
openstackkeystone>= 0 < 2013.1.2-12013.1.2-1
openstackkeystone>= 0 < 2013.1.2-12013.1.2-1
openstackkeystone>= 0 < 2013.1.2-12013.1.2-1
openstackkeystone>= 0 < 2013.1.2-12013.1.2-1
openstackkeystone2012.2 – 2012.2.4
openstackkeystone>= 2013.1 < 2013.1.32013.1.3
openstackkeystone2013.2 – 2013.2.4

CVSS provenance

nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
vendor_ubuntu5.5MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.