|
|
| |
|
| |
openstack-keystone: authentication bypass
| Package(s): | openstack-keystone |
CVE #(s): | CVE-2013-2157
|
| Created: | June 28, 2013 |
Updated: | August 12, 2013 |
| Description: |
From the openSUSE bug report:
Jose Castro Leon from CERN reported a vulnerability in the way the
Keystone LDAP backend authenticates users. When provided with an empty
password, the backend would perform an anonymous LDAP bind that would
result in successfully authenticating the user. An attacker could
therefore easily impersonate and get valid tokens for any user. Only
Keystone setups using LDAP authentication backend are affected. |
| Alerts: |
|
( Log in to post comments)
|
|
|