Описание
An issue was discovered in OpenStack Horizon 25.6 and 25.7 before 25.7.3. There is a write operation to the session storage backend before authentication and thus storage can be exhausted by unauthenticated requests. This is a regression of the CVE-2014-8124 fix.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| horizon | fixed | 3:25.7.3-1 | package | |
| horizon | not-affected | trixie | package | |
| horizon | not-affected | bookworm | package | |
| horizon | not-affected | bullseye | package |
Примечания
https://www.openwall.com/lists/oss-security/2026/05/05/7
https://bugs.launchpad.net/horizon/+bug/2150331
EPSS
Связанные уязвимости
An issue was discovered in OpenStack Horizon 25.6 and 25.7 before 25.7.3. There is a write operation to the session storage backend before authentication and thus storage can be exhausted by unauthenticated requests. This is a regression of the CVE-2014-8124 fix.
An issue was discovered in OpenStack Horizon 25.6 and 25.7 before 25.7.3. There is a write operation to the session storage backend before authentication and thus storage can be exhausted by unauthenticated requests. This is a regression of the CVE-2014-8124 fix.
EPSS