CVE Vulnerabilities

CVE-2013-2255

Improper Certificate Validation

Published: Nov 01, 2019 | Modified: Nov 07, 2019
CVSS 3.x
5.9
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
4.3 MODERATE
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V3
Ubuntu
LOW

HTTPSConnections in OpenStack Keystone 2013, OpenStack Compute 2013.1, and possibly other OpenStack components, fail to validate server-side SSL certificates.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Affected Software

Name Vendor Start Version End Version
Compute Openstack 2013.1 (including) 2013.1 (including)
Keystone Openstack 2013 (including) 2013 (including)
Openstack Redhat 3.0 (including) 3.0 (including)
Openstack Redhat 4.0 (including) 4.0 (including)
Cinder Ubuntu devel *
Cinder Ubuntu quantal *
Cinder Ubuntu raring *
Keystone Ubuntu devel *
Keystone Ubuntu precise *
Keystone Ubuntu quantal *
Keystone Ubuntu raring *
Nova Ubuntu devel *
Nova Ubuntu precise *
Nova Ubuntu quantal *
Nova Ubuntu raring *
Python-keystoneclient Ubuntu devel *
Python-keystoneclient Ubuntu precise *
Python-keystoneclient Ubuntu quantal *
Python-keystoneclient Ubuntu raring *
Python-keystoneclient Ubuntu upstream *
Quantum Ubuntu precise *
Quantum Ubuntu quantal *
Quantum Ubuntu raring *

Potential Mitigations

References