CVE-2013-2255
MEDIUMOpenstack Compute < 0.4.0 - Improper Certificate Validation
Title source: ruleDescription
HTTPSConnections in OpenStack Keystone 2013, OpenStack Compute 2013.1, and possibly other OpenStack components, fail to validate server-side SSL certificates.
References (7)
Scores
CVSS v3
5.9
EPSS
0.0041
EPSS Percentile
61.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Classification
CWE
CWE-295
Status
published
Affected Products (11)
openstack/compute
openstack/keystone
redhat/openstack
redhat/openstack
debian/debian_linux
debian/debian_linux
debian/debian_linux
pypi/python-keystoneclient
< 0.4.0PyPI
pypi/cinder
< 7.0.0a0PyPI
pypi/neutron
< 7.0.0a0PyPI
pypi/keystone
< 8.0.0a0PyPI
Timeline
Published
Nov 01, 2019
Tracked Since
Feb 18, 2026