A flaw was found in OpenStack Keystone. A remote attacker could exploit this vulnerability by sending a large HTTP request, specifically by providing a long tenant name when requesting a token. This could lead to a denial of service, consuming excessive CPU and memory resources on the affected system.
Attack Parameters
Impact Assessment
CVSS Vector v3.1
Weakness Type (CWE)
Vulnerable Products 5
| Configuration | From (including) | Up to (excluding) |
|---|---|---|
|
Openstack Keystone
cpe:2.3:a:openstack:keystone:*:*:*:*:*:*:*:*
|
2012.1
|
<= 2012.1.3
|
|
Openstack Keystone
cpe:2.3:a:openstack:keystone:*:*:*:*:*:*:*:*
|
2012.2
|
<= 2012.2.4
|
|
Openstack Keystone
cpe:2.3:a:openstack:keystone:2013.1:milestone1:*:*:*:*:*:*
|
— | — |
|
Openstack Keystone
cpe:2.3:a:openstack:keystone:2013.1:milestone2:*:*:*:*:*:*
|
— | — |
|
Openstack Keystone
cpe:2.3:a:openstack:keystone:2013.1:milestone3:*:*:*:*:*:*
|
— | — |