cbcvebase.
CVE-2013-2255
published 2019-11-01

CVE-2013-2255: HTTPSConnections in OpenStack Keystone 2013, OpenStack Compute 2013.1, and possibly other OpenStack components, fail to validate server-side SSL certificates.

PriorityP425medium5.9CVSS 3.1
AVNACHPRNUINSUCNIHAN
EPSS
0.96%
57.7th percentile
HTTPSConnections in OpenStack Keystone 2013, OpenStack Compute 2013.1, and possibly other OpenStack components, fail to validate server-side SSL certificates.

Affected

16 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debiandebian_linux
debiankeystone< keystone 2014.1-1 (bookworm)keystone 2014.1-1 (bookworm)
debianswift< keystone 2014.1-1 (bookworm)keystone 2014.1-1 (bookworm)
openstackcinder>= 0 < 7.0.0a07.0.0a0
openstackcompute
openstackkeystone
openstackkeystone>= 0 < 2014.1-12014.1-1
openstackkeystone>= 0 < 2014.1-12014.1-1
openstackkeystone>= 0 < 2014.1-12014.1-1
openstackkeystone>= 0 < 2014.1-12014.1-1
openstackkeystone>= 0 < 8.0.0a08.0.0a0
openstackneutron>= 0 < 7.0.0a07.0.0a0
redhatopenstack
redhatopenstack

CVSS provenance

nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv5.9MEDIUM
vendor_debian5.9MEDIUM
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.