CVE-2013-0247
Publication date 5 February 2013
Last updated 24 July 2024
Ubuntu priority
OpenStack Keystone Essex 2012.1.3 and earlier, Folsom 2012.2.3 and earlier, and Grizzly grizzly-2 and earlier allows remote attackers to cause a denial of service (disk consumption) via many invalid token requests that trigger excessive generation of log entries.
Notes
jdstrand
Keystone on 11.10 is a pre-release version and unusable with other components such as nova and horizon 2013.1~g2-0ubuntu1 is affected. Server team will provide this as part of their regular updates for Ubuntu 13.04 (deferring for now) reproducer in the bug
References
Related Ubuntu Security Notices (USN)
- USN-1715-1
- OpenStack Keystone vulnerability
- 5 February 2013