Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-43002

Опубликовано: 05 мая 2026
Источник: debian
EPSS Низкий

Описание

An issue was discovered in OpenStack Horizon 25.6 and 25.7 before 25.7.3. There is a write operation to the session storage backend before authentication and thus storage can be exhausted by unauthenticated requests. This is a regression of the CVE-2014-8124 fix.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
horizonfixed3:25.7.3-1package
horizonnot-affectedtrixiepackage
horizonnot-affectedbookwormpackage
horizonnot-affectedbullseyepackage

Примечания

  • https://www.openwall.com/lists/oss-security/2026/05/05/7

  • https://bugs.launchpad.net/horizon/+bug/2150331

EPSS

Процентиль: 30%
0.00365
Низкий

Связанные уязвимости

CVSS3: 5.3
ubuntu
3 месяца назад

An issue was discovered in OpenStack Horizon 25.6 and 25.7 before 25.7.3. There is a write operation to the session storage backend before authentication and thus storage can be exhausted by unauthenticated requests. This is a regression of the CVE-2014-8124 fix.

CVSS3: 5.3
nvd
3 месяца назад

An issue was discovered in OpenStack Horizon 25.6 and 25.7 before 25.7.3. There is a write operation to the session storage backend before authentication and thus storage can be exhausted by unauthenticated requests. This is a regression of the CVE-2014-8124 fix.

CVSS3: 5.3
github
3 месяца назад

OpenStack Horizon has Incorrect Behavior Order

EPSS

Процентиль: 30%
0.00365
Низкий