OpenStack Keystone Essex 2012.1.3 and earlier, Folsom 2012.2.3 and earlier, and Grizzly grizzly-2 and earlier allows remote attackers to cause a denial of service (disk consumption) via many invalid token requests that trigger excessive generation of log entries.
CVSS Details
- CVSS 3.1 Base Score: 5.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade keystone | Jul 30, 2024 | Feb 24, 2013 |
| Suse | — | Upgrade python-swiftUpgrade openstack-nova-objectstoreUpgrade openstack-swift-containerUpgrade openstack-swift-proxyUpgrade openstack-swiftUpgrade openstack-swift-accountUpgrade python-glanceUpgrade python-cinderclient-docUpgrade openstack-keystoneUpgrade openstack-nova-novncproxyUpgrade openstack-quickstartUpgrade python-cinderclient-testUpgrade openstack-nova-docUpgrade python-novaUpgrade openstack-nova-apiUpgrade openstack-dashboardUpgrade openstack-nova-networkUpgrade openstack-nova-vncproxyUpgrade openstack-quantumUpgrade python-quantumUpgrade openstack-nova-testUpgrade openstack-cinder-docUpgrade python-keystoneclient-docUpgrade python-cinderclientUpgrade openstack-dashboard-testUpgrade openstack-cinderUpgrade openstack-cinder-apiUpgrade openstack-swift-testUpgrade openstack-nova-volumeUpgrade openstack-cinder-testUpgrade openstack-glanceUpgrade python-horizonUpgrade openstack-quantum-docUpgrade openstack-quantum-testUpgrade openstack-keystone-testUpgrade python-keystoneclientUpgrade openstack-glance-testUpgrade openstack-swift-objectUpgrade openstack-swift-docUpgrade python-django_openstack_authUpgrade openstack-keystone-docUpgrade openstack-novaUpgrade openstack-nova-schedulerUpgrade python-keystoneclient-testUpgrade openstack-nova-computeUpgrade openstack-glance-docUpgrade openstack-cinder-schedulerUpgrade python-cinderUpgrade openstack-cinder-volumeUpgrade openstack-nova-certUpgrade python-keystone | Dec 12, 2013 | Feb 24, 2013 |
| Ubuntu | — | Upgrade python-keystone | Nov 8, 2024 | Feb 24, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub