CVE Vulnerabilities

CVE-2013-2255

Improper Certificate Validation

Published: Nov 01, 2019 | Modified: Nov 07, 2019
CVSS 3.x
5.9
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

HTTPSConnections in OpenStack Keystone 2013, OpenStack Compute 2013.1, and possibly other OpenStack components, fail to validate server-side SSL certificates.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Affected Software

Name Vendor Start Version End Version
Compute Openstack 2013.1 (including) 2013.1 (including)
Keystone Openstack 2013 (including) 2013 (including)
Openstack Redhat 3.0 (including) 3.0 (including)
Openstack Redhat 4.0 (including) 4.0 (including)

Potential Mitigations

References