Security Advisory
CVE-2013-2157
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
OpenStack Keystone Folsom, Grizzly before 2013.1.3, and Havana, when using LDAP with Anonymous binding, allows remote attackers to bypass authentication via an empty password.