Page 2 of 12 results (0.002 seconds)

CVSS: 7.5EPSS: 0%CPEs: 5EXPL: 0

12 Apr 2013 — OpenStack Keystone Grizzly before 2013.1, Folsom 2012.1.3 and earlier, and Essex does not properly check if the (1) user, (2) tenant, or (3) domain is enabled when using EC2-style authentication, which allows context-dependent attackers to bypass access restrictions. OpenStack Keystone Grizzly antes de v2013.1, Folsom v2012.1.3 y anteriores, y Essex no comprueba correctamente si (1) el usuario, (2) el inquilino, o (3) el dominio está habilitada cuando se utiliza autenticación EC2-style, lo que permite eludi... • http://www.openwall.com/lists/oss-security/2013/02/19/3 • CWE-287: Improper Authentication •

CVSS: 7.5EPSS: 3%CPEs: 5EXPL: 0

24 Feb 2013 — OpenStack Keystone Essex 2012.1.3 and earlier, Folsom 2012.2.3 and earlier, and Grizzly grizzly-2 and earlier allows remote attackers to cause a denial of service (disk consumption) via many invalid token requests that trigger excessive generation of log entries. OpenStack Keystone Essex v2012.1.3 y anteriores, y Grizzly grizzly-2 y anteriores permiten a atacantes remotos generar una denegación de servicio (consumo de disco) mediante una solicitud de token inválida que genera una excesiva cantidad de entrad... • http://lists.fedoraproject.org/pipermail/package-announce/2013-February/098906.html • CWE-399: Resource Management Errors •