Lucene search

K
cve[email protected]CVE-2014-2828
HistoryApr 15, 2014 - 2:55 p.m.

CVE-2014-2828

2014-04-1514:55:04
CWE-287
web.nvd.nist.gov
28
cve-2014-2828
v3 api
openstack identity
keystone
denial of service
cpu consumption
remote attackers
authentication chaining

7.8 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

6.6 Medium

AI Score

Confidence

Low

0.008 Low

EPSS

Percentile

81.3%

The V3 API in OpenStack Identity (Keystone) 2013.1 before 2013.2.4 and icehouse before icehouse-rc2 allows remote attackers to cause a denial of service (CPU consumption) via a large number of the same authentication method in a request, aka “authentication chaining.”

Affected configurations

NVD
Node
openstackkeystoneMatch2013.1
OR
openstackkeystoneMatch2013.1.1
OR
openstackkeystoneMatch2013.1.2
OR
openstackkeystoneMatch2013.1.3
OR
openstackkeystoneMatch2013.2
OR
openstackkeystoneMatch2013.2.1
OR
openstackkeystoneMatch2013.2.2
OR
openstackkeystoneMatch2013.2.3

7.8 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

6.6 Medium

AI Score

Confidence

Low

0.008 Low

EPSS

Percentile

81.3%