Vulnerabilities > Openstack > Keystone > 2013.1

DATE CVE VULNERABILITY TITLE RISK
2013-04-12 CVE-2013-0270 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Openstack Keystone
OpenStack Keystone Grizzly before 2013.1, Folsom, and possibly earlier allows remote attackers to cause a denial of service (CPU and memory consumption) via a large HTTP request, as demonstrated by a long tenant_name when requesting a token.
network
low complexity
openstack CWE-119
5.0
2013-02-24 CVE-2013-0247 Resource Management Errors vulnerability in multiple products
OpenStack Keystone Essex 2012.1.3 and earlier, Folsom 2012.2.3 and earlier, and Grizzly grizzly-2 and earlier allows remote attackers to cause a denial of service (disk consumption) via many invalid token requests that trigger excessive generation of log entries.
network
low complexity
openstack canonical CWE-399
5.0