Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2014-2828

Опубликовано: 15 апр. 2014
Источник: nvd
CVSS2: 7.8
EPSS Низкий

Описание

The V3 API in OpenStack Identity (Keystone) 2013.1 before 2013.2.4 and icehouse before icehouse-rc2 allows remote attackers to cause a denial of service (CPU consumption) via a large number of the same authentication method in a request, aka "authentication chaining."

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:openstack:keystone:2013.1:*:*:*:*:*:*:*
cpe:2.3:a:openstack:keystone:2013.1.1:*:*:*:*:*:*:*
cpe:2.3:a:openstack:keystone:2013.1.2:*:*:*:*:*:*:*
cpe:2.3:a:openstack:keystone:2013.1.3:*:*:*:*:*:*:*
cpe:2.3:a:openstack:keystone:2013.2:*:*:*:*:*:*:*
cpe:2.3:a:openstack:keystone:2013.2.1:*:*:*:*:*:*:*
cpe:2.3:a:openstack:keystone:2013.2.2:*:*:*:*:*:*:*
cpe:2.3:a:openstack:keystone:2013.2.3:*:*:*:*:*:*:*

EPSS

Процентиль: 75%
0.00864
Низкий

7.8 High

CVSS2

Дефекты

CWE-287

Связанные уязвимости

ubuntu
почти 12 лет назад

The V3 API in OpenStack Identity (Keystone) 2013.1 before 2013.2.4 and icehouse before icehouse-rc2 allows remote attackers to cause a denial of service (CPU consumption) via a large number of the same authentication method in a request, aka "authentication chaining."

redhat
почти 12 лет назад

The V3 API in OpenStack Identity (Keystone) 2013.1 before 2013.2.4 and icehouse before icehouse-rc2 allows remote attackers to cause a denial of service (CPU consumption) via a large number of the same authentication method in a request, aka "authentication chaining."

debian
почти 12 лет назад

The V3 API in OpenStack Identity (Keystone) 2013.1 before 2013.2.4 and ...

CVSS3: 7.5
github
больше 3 лет назад

OpenStack Identity (Keystone) DoS through V3 API authentication chaining

EPSS

Процентиль: 75%
0.00864
Низкий

7.8 High

CVSS2

Дефекты

CWE-287