CVE-2013-2255Medium· 5.9▾ SunlitOpenStack Keystone and other components vulnerable to Improper Certificate Validation
▾ Sunlit zone — Low / medium · no exploitation signal
impact 32.5 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
1.0%
1.0% → 1.0%
HTTPSConnections in OpenStack Keystone 2013, OpenStack Compute 2013.1, and possibly other OpenStack components, fail to validate server-side SSL certificates.
python-keystoneclient < 0.4.0cinder < 7.0.0a0neutron < 7.0.0a0keystone < 8.0.0a0Upgrade to a patched release:
python-keystoneclient 0.4.0cinder 7.0.0a0neutron 7.0.0a0keystone 8.0.0a0Connected by shared product, vendor, weakness, or advisory.