Vulnerability Details CVE-2013-0270
A flaw was found in OpenStack Keystone. A remote attacker could exploit this vulnerability by sending a large HTTP request, specifically by providing a long tenant name when requesting a token. This could lead to a denial of service, consuming excessive CPU and memory resources on the affected system.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.027
EPSS Ranking 85.9%
CVSS Severity
CVSS v3 Score 6.5
CVSS v2 Score 5.0
Products affected by CVE-2013-0270
-
cpe:2.3:a:openstack:keystone:2012.1
-
cpe:2.3:a:openstack:keystone:2012.1.1
-
cpe:2.3:a:openstack:keystone:2012.1.2
-
cpe:2.3:a:openstack:keystone:2012.1.3
-
cpe:2.3:a:openstack:keystone:2012.2
-
cpe:2.3:a:openstack:keystone:2012.2.1
-
cpe:2.3:a:openstack:keystone:2012.2.2
-
cpe:2.3:a:openstack:keystone:2012.2.3
-
cpe:2.3:a:openstack:keystone:2012.2.4
-
cpe:2.3:a:openstack:keystone:2013.1