Vulnerability Name: | CVE-2013-2014 (CCN-84347) | ||||||||
Assigned: | 2013-01-13 | ||||||||
Published: | 2013-01-13 | ||||||||
Updated: | 2020-06-02 | ||||||||
Summary: | OpenStack Identity (Keystone) before 2013.1 allows remote attackers to cause a denial of service (memory consumption and crash) via multiple long requests. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
| ||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P) 4.3 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P/E:H/RL:OF/RC:C)
4.3 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P/E:H/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-20 | ||||||||
Vulnerability Consequences: | Denial of Service | ||||||||
References: | Source: MITRE Type: CNA CVE-2013-2014 Source: CCN Type: OpenStack Keystone Web Site OpenStack Keystone Source: FEDORA Type: Third Party Advisory FEDORA-2013-10467 Source: CCN Type: SA53397 OpenStack Keystone HTTP Request Processing Denial of Service Vulnerability Source: SECUNIA Type: Third Party Advisory 53397 Source: BID Type: Third Party Advisory, VDB Entry 59936 Source: CCN Type: BID-59936 OpenStack Keystone CVE-2013-2014 Denial of Service Vulnerability Source: CONFIRM Type: Issue Tracking, Third Party Advisory https://bugs.launchpad.net/keystone/+bug/1098177 Source: CCN Type: OpenStack Bug #1099025 block really large requests Source: CONFIRM Type: Issue Tracking, Third Party Advisory https://bugs.launchpad.net/keystone/+bug/1099025 Source: XF Type: UNKNOWN openstack-keystone-cve20132014-http-dos(84347) Source: XF Type: VDB Entry openstack-keystone-cve20132014-http-dos(84347) Source: CCN Type: OpenStack Review Web Site Limit the size of HTTP requests Source: CCN Type: WhiteSource Vulnerability Database CVE-2013-2014 | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: ![]() | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |