CVE-2013-0270
OpenStack Keystone Denial of Service vulnerability via a large HTTP request
Description
A flaw was found in OpenStack Keystone. A remote attacker could exploit this vulnerability by sending a large HTTP request, specifically by providing a long tenant name when requesting a token. This could lead to a denial of service, consuming excessive CPU and memory resources on the affected system.
Metrics
Weakness classes (CWE)
CWE-1284Base
Improper Validation of Specified Quantity in Input
The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties.
cwe.mitre.org →
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- CVE Modified2026-07-30 14:16 UTC· secalert@redhat.com
- Reference: https://access.redhat.com/errata/RHSA-2013:0708
- Affected: Red Hat OpenStack Platform 13 (Queens), Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 16.2 (+4) → OpenStack Folsom for RHEL 6, Red Hat OpenStack Platform 13 (Queens), Red Hat OpenStack Platform 16.2 (+5)
Affected products
Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.
openstack
keystone2012.1 – 2012.1.3
openstack
keystone2012.2 – 2012.2.4
openstack
keystone
References & sources
- https://nvd.nist.gov/vuln/detail/CVE-2013-0270advisory
- https://github.com/openstack/keystone/commit/7691276b869a86c2b75631d5bede9f61e030d9d8web
- https://github.com/openstack/keystone/commit/82c87e5638ebaf9f166a9b07a0155291276d6fdcweb
- https://access.redhat.com/security/cve/CVE-2013-0270web
- https://bugs.launchpad.net/keystone/+bug/1099025web
- https://bugzilla.redhat.com/show_bug.cgi?id=909012web
- https://launchpad.net/keystone/grizzly/2013.1web
- http://rhn.redhat.com/errata/RHSA-2013-0708.htmlweb
- https://pypi.org/project/keystonepackage
- https://github.com/advisories/GHSA-4ppj-4p4v-jf4padvisory
- https://access.redhat.com/errata/RHSA-2013:0708vendor-advisoryx_refsource_REDHAT