CVE-2013-0282: Openstack Keystone
Medium severity, CVSS 5.0. EPSS: 1.8% chance of exploitation in the next 30 days.
OpenStack Keystone Grizzly before 2013.1, Folsom 2012.1.3 and earlier, and Essex does not properly check if the (1) user, (2) tenant, or (3) domain is enabled when using EC2-style authentication, which allows context-dependent attackers to bypass access restrictions.
Affected products
- Openstack Keystone: from 2012.1, up to and including 2012.1.3; from 2012.2, up to and including 2012.2.4; version 2013.1 only
Published 2013-04-12. Last modified 2026-06-16.