Lucene search

K
cve[email protected]CVE-2014-8124
HistoryDec 12, 2014 - 3:59 p.m.

CVE-2014-8124

2014-12-1215:59:09
CWE-400
web.nvd.nist.gov
27
cve-2014-8124
openstack
horizon
denial of service
session management
vulnerability

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

6.6 Medium

AI Score

Confidence

Low

0.018 Low

EPSS

Percentile

88.1%

OpenStack Dashboard (Horizon) before 2014.1.3 and 2014.2.x before 2014.2.1 does not properly handle session records when using a db or memcached session engine, which allows remote attackers to cause a denial of service via a large number of requests to the login page.

Affected configurations

NVD
Node
openstackhorizonRange2014.12014.1.3
OR
openstackhorizonRange2014.2.02014.2.1
Node
fedoraprojectfedoraMatch21
Node
opensuseopensuseMatch13.1
Node
oraclesolarisMatch11.2

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

6.6 Medium

AI Score

Confidence

Low

0.018 Low

EPSS

Percentile

88.1%