cbcvebase.
CVE-2013-2255
published 2019-11-01

CVE-2013-2255: HTTPSConnections in OpenStack Keystone 2013, OpenStack Compute 2013.1, and possibly other OpenStack components, fail to validate server-side SSL certificates.

medium5.9CVSS 3.1
AVNACHPRNUINSUCNIHAN
HTTPSConnections in OpenStack Keystone 2013, OpenStack Compute 2013.1, and possibly other OpenStack components, fail to validate server-side SSL certificates.

Affected

16 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debiandebian_linux
debiankeystone< keystone 2014.1-1 (bookworm)keystone 2014.1-1 (bookworm)
debianswift< keystone 2014.1-1 (bookworm)keystone 2014.1-1 (bookworm)
openstackcinder>= 0 < 7.0.0a07.0.0a0
openstackcompute
openstackkeystone
openstackkeystone>= 0 < 2014.1-12014.1-1
openstackkeystone>= 0 < 2014.1-12014.1-1
openstackkeystone>= 0 < 2014.1-12014.1-1
openstackkeystone>= 0 < 2014.1-12014.1-1
openstackkeystone>= 0 < 8.0.0a08.0.0a0
openstackneutron>= 0 < 7.0.0a07.0.0a0
redhatopenstack
redhatopenstack

CVSS provenance

nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
osv5.9MEDIUM