OpenStack Keystone CVE-2013-2006 LDAP Password Information Disclosure Vulnerability
BID:59411
Info
OpenStack Keystone CVE-2013-2006 LDAP Password Information Disclosure Vulnerability
| Bugtraq ID: | 59411 |
| Class: | Design Error |
| CVE: |
CVE-2013-2006 |
| Remote: | No |
| Local: | Yes |
| Published: | Apr 23 2013 12:00AM |
| Updated: | Apr 13 2015 09:21PM |
| Credit: | Xu Han Peng |
| Vulnerable: |
Redhat OpenStack Folsom 0 OpenStack Keystone 0 |
| Not Vulnerable: | |
Discussion
OpenStack Keystone CVE-2013-2006 LDAP Password Information Disclosure Vulnerability
Keystone is prone to an information-disclosure vulnerability.
Successfully exploiting this issue may allow attackers to obtain sensitive information such as LDAP passwords that may aid in further attacks.
Keystone is prone to an information-disclosure vulnerability.
Successfully exploiting this issue may allow attackers to obtain sensitive information such as LDAP passwords that may aid in further attacks.
Solution / Fix
OpenStack Keystone CVE-2013-2006 LDAP Password Information Disclosure Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
OpenStack Keystone CVE-2013-2006 LDAP Password Information Disclosure Vulnerability
References:
References:
- Code Review: keystone/common/config.py (OpenStack)
- CVE-2013-2006 OpenStack keystone LDAP password disclosure in log files (Openwall)
- LDAP password and admin_token should be secret (OpenStack)
- Low: openstack-keystone security and bug fix update (Red Hat)
- OpenStack Keystone Homepage (OpenStack )