CVE-2013-0282
Publication date 19 February 2013
Last updated 24 July 2024
Ubuntu priority
OpenStack Keystone Grizzly before 2013.1, Folsom 2012.1.3 and earlier, and Essex does not properly check if the (1) user, (2) tenant, or (3) domain is enabled when using EC2-style authentication, which allows context-dependent attackers to bypass access restrictions.
Notes
jdstrand
Keystone on 11.10 is a pre-release version and unusable with other components such as nova and horizon
References
Related Ubuntu Security Notices (USN)
- USN-1730-1
- OpenStack Keystone vulnerabilities
- 20 February 2013