Release date:
Updated on: 2013-02-27
Affected Systems:
Openstack Keystone
Description:
--------------------------------------------------------------------------------
Bugtraq id: 57747
CVE (CAN) ID: CVE-2013-0247
OpenStack Keystone is a project that provides identity, Token, directory, and policy services for the OpenStack series.
OpenStack Keystone Essex 2012.1.3, Folsom 2012.2.3, and Grizzly grizzly-2 allow remote attackers to generate too many log entries through a large number of invalid token requests, resulting in denial of service (Disk consumption ).
<* Source: Dan Prince
Link: https://bugzilla.redhat.com/show_bug.cgi? Id = 906171
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Openstack
---------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://horizon.openstack.org/intro.html