Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2014-2828

Опубликовано: 15 апр. 2014
Источник: nvd
CVSS2: 7.8
EPSS Низкий

Описание

The V3 API in OpenStack Identity (Keystone) 2013.1 before 2013.2.4 and icehouse before icehouse-rc2 allows remote attackers to cause a denial of service (CPU consumption) via a large number of the same authentication method in a request, aka "authentication chaining."

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:openstack:keystone:2013.1:*:*:*:*:*:*:*
cpe:2.3:a:openstack:keystone:2013.1.1:*:*:*:*:*:*:*
cpe:2.3:a:openstack:keystone:2013.1.2:*:*:*:*:*:*:*
cpe:2.3:a:openstack:keystone:2013.1.3:*:*:*:*:*:*:*
cpe:2.3:a:openstack:keystone:2013.2:*:*:*:*:*:*:*
cpe:2.3:a:openstack:keystone:2013.2.1:*:*:*:*:*:*:*
cpe:2.3:a:openstack:keystone:2013.2.2:*:*:*:*:*:*:*
cpe:2.3:a:openstack:keystone:2013.2.3:*:*:*:*:*:*:*

EPSS

Процентиль: 87%
0.03155
Низкий

7.8 High

CVSS2

Дефекты

CWE-287

Связанные уязвимости

ubuntu
больше 12 лет назад

The V3 API in OpenStack Identity (Keystone) 2013.1 before 2013.2.4 and icehouse before icehouse-rc2 allows remote attackers to cause a denial of service (CPU consumption) via a large number of the same authentication method in a request, aka "authentication chaining."

redhat
больше 12 лет назад

The V3 API in OpenStack Identity (Keystone) 2013.1 before 2013.2.4 and icehouse before icehouse-rc2 allows remote attackers to cause a denial of service (CPU consumption) via a large number of the same authentication method in a request, aka "authentication chaining."

debian
больше 12 лет назад

The V3 API in OpenStack Identity (Keystone) 2013.1 before 2013.2.4 and ...

CVSS3: 7.5
github
около 4 лет назад

OpenStack Identity (Keystone) DoS through V3 API authentication chaining

EPSS

Процентиль: 87%
0.03155
Низкий

7.8 High

CVSS2

Дефекты

CWE-287