Vulnerability Details CVE-2013-0270
OpenStack Keystone Grizzly before 2013.1, Folsom, and possibly earlier allows remote attackers to cause a denial of service (CPU and memory consumption) via a large HTTP request, as demonstrated by a long tenant_name when requesting a token.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.018
EPSS Ranking 81.8%
CVSS Severity
CVSS v2 Score 5.0
Products affected by CVE-2013-0270
-
cpe:2.3:a:openstack:keystone:2012.1
-
cpe:2.3:a:openstack:keystone:2012.1.1
-
cpe:2.3:a:openstack:keystone:2012.1.2
-
cpe:2.3:a:openstack:keystone:2012.1.3
-
cpe:2.3:a:openstack:keystone:2012.2
-
cpe:2.3:a:openstack:keystone:2012.2.1
-
cpe:2.3:a:openstack:keystone:2012.2.2
-
cpe:2.3:a:openstack:keystone:2012.2.3
-
cpe:2.3:a:openstack:keystone:2012.2.4
-
cpe:2.3:a:openstack:keystone:2013.1