CVE-2013-2255
published 2019-11-01CVE-2013-2255: HTTPSConnections in OpenStack Keystone 2013, OpenStack Compute 2013.1, and possibly other OpenStack components, fail to validate server-side SSL certificates.
PriorityP425medium5.9CVSS 3.1
AVNACHPRNUINSUCNIHAN
EPSS
0.96%
57.7th percentile
HTTPSConnections in OpenStack Keystone 2013, OpenStack Compute 2013.1, and possibly other OpenStack components, fail to validate server-side SSL certificates.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | keystone | < keystone 2014.1-1 (bookworm) | keystone 2014.1-1 (bookworm) |
| debian | swift | < keystone 2014.1-1 (bookworm) | keystone 2014.1-1 (bookworm) |
| openstack | cinder | >= 0 < 7.0.0a0 | 7.0.0a0 |
| openstack | compute | — | — |
| openstack | keystone | — | — |
| openstack | keystone | >= 0 < 2014.1-1 | 2014.1-1 |
| openstack | keystone | >= 0 < 2014.1-1 | 2014.1-1 |
| openstack | keystone | >= 0 < 2014.1-1 | 2014.1-1 |
| openstack | keystone | >= 0 < 2014.1-1 | 2014.1-1 |
| openstack | keystone | >= 0 < 8.0.0a0 | 8.0.0a0 |
| openstack | neutron | >= 0 < 7.0.0a0 | 7.0.0a0 |
| redhat | openstack | — | — |
| redhat | openstack | — | — |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv5.9MEDIUM
vendor_debian5.9MEDIUM
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
openstack-*: Inconsistent and non-validating HTTPS client
vendor_redhat·2013-07-10·CVSS 5.9
CVE-2013-2255 [MEDIUM] openstack-*: Inconsistent and non-validating HTTPS client
openstack-*: Inconsistent and non-validating HTTPS client
HTTPSConnections in OpenStack Keystone 2013, OpenStack Compute 2013.1, and possibly other OpenStack components, fail to validate server-side SSL certificates.
Statement: The Red Hat Security Response Team has rated this issue as having Moderate security impact in RedHat Enterprise OpenStack Platform 3 however fixing this issue would require a change to default behavior. This issue is not currently planned to be addressed in future updates.
This issue did not affect the versions of openstack-keystone or python-keystone client as shipped with RedHat Enterprise OpenStack Platform 4.
For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Package: openstack-k
Debian
CVE-2013-2255: keystone - HTTPSConnections in OpenStack Keystone 2013, OpenStack Compute 2013.1, and possi...
vendor_debian·2013·CVSS 5.9
CVE-2013-2255 [MEDIUM] CVE-2013-2255: keystone - HTTPSConnections in OpenStack Keystone 2013, OpenStack Compute 2013.1, and possi...
HTTPSConnections in OpenStack Keystone 2013, OpenStack Compute 2013.1, and possibly other OpenStack components, fail to validate server-side SSL certificates.
Scope: local
bookworm: resolved (fixed in 2014.1-1)
bullseye: resolved (fixed in 2014.1-1)
forky: resolved (fixed in 2014.1-1)
sid: resolved (fixed in 2014.1-1)
trixie: resolved (fixed in 2014.1-1)
GHSA
OpenStack Keystone and other components vulnerable to Improper Certificate Validation
ghsa·2022-05-05
CVE-2013-2255 [MEDIUM] CWE-295 OpenStack Keystone and other components vulnerable to Improper Certificate Validation
OpenStack Keystone and other components vulnerable to Improper Certificate Validation
HTTPSConnections in OpenStack Keystone 2013, OpenStack Compute 2013.1, and possibly other OpenStack components, fail to validate server-side SSL certificates.
OSV
OpenStack Keystone and other components vulnerable to Improper Certificate Validation
osv·2022-05-05
CVE-2013-2255 [MEDIUM] OpenStack Keystone and other components vulnerable to Improper Certificate Validation
OpenStack Keystone and other components vulnerable to Improper Certificate Validation
HTTPSConnections in OpenStack Keystone 2013, OpenStack Compute 2013.1, and possibly other OpenStack components, fail to validate server-side SSL certificates.
OSV
CVE-2013-2255: HTTPSConnections in OpenStack Keystone 2013, OpenStack Compute 2013
osv·2019-11-01·CVSS 5.9
CVE-2013-2255 [MEDIUM] CVE-2013-2255: HTTPSConnections in OpenStack Keystone 2013, OpenStack Compute 2013
HTTPSConnections in OpenStack Keystone 2013, OpenStack Compute 2013.1, and possibly other OpenStack components, fail to validate server-side SSL certificates.
No detection rules found.
No public exploits indexed.
Bugzilla
python-keystoneclient: CVE-2013-2255 Inconsistent and non-validating HTTPS client [epel-6]
bugzilla·2013-07-15·CVSS 5.9
CVE-2013-2255 [MEDIUM] python-keystoneclient: CVE-2013-2255 Inconsistent and non-validating HTTPS client [epel-6]
python-keystoneclient: CVE-2013-2255 Inconsistent and non-validating HTTPS client [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
epel-6 tr
Bugzilla
python-keystoneclient: CVE-2013-2255 Inconsistent and non-validating HTTPS client [fedora-all]
bugzilla·2013-07-15·CVSS 5.9
CVE-2013-2255 [MEDIUM] python-keystoneclient: CVE-2013-2255 Inconsistent and non-validating HTTPS client [fedora-all]
python-keystoneclient: CVE-2013-2255 Inconsistent and non-validating HTTPS client [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please not
Bugzilla
openstack-keystone: CVE-2013-2255 Inconsistent and non-validating HTTPS client [fedora-all]
bugzilla·2013-07-15·CVSS 5.9
CVE-2013-2255 [MEDIUM] openstack-keystone: CVE-2013-2255 Inconsistent and non-validating HTTPS client [fedora-all]
openstack-keystone: CVE-2013-2255 Inconsistent and non-validating HTTPS client [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note:
Bugzilla
openstack-keystone: CVE-2013-2255 Inconsistent and non-validating HTTPS client [epel-6]
bugzilla·2013-07-15·CVSS 5.9
CVE-2013-2255 [MEDIUM] openstack-keystone: CVE-2013-2255 Inconsistent and non-validating HTTPS client [epel-6]
openstack-keystone: CVE-2013-2255 Inconsistent and non-validating HTTPS client [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
epel-6 track
Bugzilla
CVE-2013-2255 openstack-*: Inconsistent and non-validating HTTPS client
bugzilla·2013-03-21·CVSS 5.9
CVE-2013-2255 [MEDIUM] CVE-2013-2255 openstack-*: Inconsistent and non-validating HTTPS client
CVE-2013-2255 openstack-*: Inconsistent and non-validating HTTPS client
Description:
The following files use httplib.HTTPSConnection :
keystone/middleware/s3_token.py
keystone/middleware/ec2_token.py
keystone/common/bufferedhttp.py
vendor/python-keystoneclient-master/keystoneclient/middleware/auth_token.py
AFAICT HTTPSConnection does not validate server certificates and should be avoided. This is fixed in Python 3, however in 2.X no validation occurs. I suspect this is also applicable to most OpenStack modules that make HTTPS client calls.
Discussion:
(In reply to Grant Murphy from comment #0)
Thank you for your report, Grant.
> Description:
>
> The following files use httplib.HTTPSConnection :
>
> keystone/middleware/s3_token.py
> keystone/middleware/ec2_token.py
> keystone/commo
https://access.redhat.com/security/cve/cve-2013-2255https://bugs.launchpad.net/ossn/+bug/1188189https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-2255https://bugzilla.suse.com/show_bug.cgi?id=CVE-2013-2255https://exchange.xforce.ibmcloud.com/vulnerabilities/85562https://security-tracker.debian.org/tracker/CVE-2013-2255https://www.securityfocus.com/bid/61118https://access.redhat.com/security/cve/cve-2013-2255https://bugs.launchpad.net/ossn/+bug/1188189https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-2255https://bugzilla.suse.com/show_bug.cgi?id=CVE-2013-2255https://exchange.xforce.ibmcloud.com/vulnerabilities/85562https://security-tracker.debian.org/tracker/CVE-2013-2255https://www.securityfocus.com/bid/61118
2019-11-01
Published