CVE-2013-2157: Openstack Keystone
Medium severity, CVSS 4.3. EPSS: 3.1% chance of exploitation in the next 30 days.
OpenStack Keystone Folsom, Grizzly before 2013.1.3, and Havana, when using LDAP with Anonymous binding, allows remote attackers to bypass authentication via an empty password.
Affected products
- Openstack Keystone: from 2012.2, up to and including 2012.2.4; from 2013.1, before 2013.1.3 (fixed in 2013.1.3); from 2013.2, up to and including 2013.2.4
Published 2013-08-20. Last modified 2026-06-16.