ossa/ossa/OSSA-2013-003.yaml

60 lines
1.2 KiB
YAML

date: 2013-02-05
id: OSSA-2013-003
title: 'Keystone denial of service through invalid token requests'
description: 'Dan Prince of Red Hat reported a vulnerability in token creation error
handling in Keystone. By requesting lots of invalid tokens, an unauthenticated user
may fill up logs on Keystone API servers disks, potentially resulting in a denial
of service attack against Keystone. '
reference: http://lists.openstack.org/pipermail/openstack-announce/2013-February/000074.html
affected-products:
- product: keystone
version: All versions
vulnerabilities:
- cve-id: CVE-2013-0247
impact-assessment:
source: 'Red Hat Product Security'
rating: moderate
assessment:
type: CVSS2
score: 5.0
detail: AV:N/AC:L/Au:N/C:N/I:N/A:P
classification:
source: 'Red Hat Product Security'
type: CWE
detail: TODO
reporters:
- name: 'Dan Prince'
affiliation: 'Red Hat'
reported:
- CVE-2013-0247
issues:
links:
- https://launchpad.net/bugs/1098307
type: launchpad
reviews:
grizzly:
- https://review.openstack.org/#/c/21213
folsom:
- https://review.openstack.org/#/c/21215
essex:
- https://review.openstack.org/#/c/21216
type: gerrit