Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-8124

Опубликовано: 09 дек. 2014
Источник: redhat
CVSS2: 4.3

Описание

OpenStack Dashboard (Horizon) before 2014.1.3 and 2014.2.x before 2014.2.1 does not properly handle session records when using a db or memcached session engine, which allows remote attackers to cause a denial of service via a large number of requests to the login page.

A denial of service flaw was found in the OpenStack Dashboard (horizon) when using the db or memcached session engine. An attacker could make repeated requests to the login page, which would result in a large number of unwanted backend session entries, possibly leading to a denial of service.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux OpenStack Platform 6 (Juno)python-django-horizonNot affected
Red Hat Enterprise Linux OpenStack Platform 6 (Juno)python-django-openstack-authNot affected
Red Hat OpenStack Platform 4python-django-horizonWill not fix
Red Hat OpenStack Platform 4python-django-openstack-authWill not fix
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6python-django-horizonFixedRHSA-2015:084516.04.2015
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6python-django-openstack-authFixedRHSA-2015:084516.04.2015
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7python-django-horizonFixedRHSA-2015:083916.04.2015
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7python-django-openstack-authFixedRHSA-2015:083916.04.2015

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=1169637python-django-horizon: denial of service via login page requests

4.3 Medium

CVSS2

Связанные уязвимости

ubuntu
около 11 лет назад

OpenStack Dashboard (Horizon) before 2014.1.3 and 2014.2.x before 2014.2.1 does not properly handle session records when using a db or memcached session engine, which allows remote attackers to cause a denial of service via a large number of requests to the login page.

nvd
около 11 лет назад

OpenStack Dashboard (Horizon) before 2014.1.3 and 2014.2.x before 2014.2.1 does not properly handle session records when using a db or memcached session engine, which allows remote attackers to cause a denial of service via a large number of requests to the login page.

debian
около 11 лет назад

OpenStack Dashboard (Horizon) before 2014.1.3 and 2014.2.x before 2014 ...

github
больше 3 лет назад

OpenStack Dashboard (Horizon) before 2014.1.3 and 2014.2.x before 2014.2.1 does not properly handle session records when using a db or memcached session engine, which allows remote attackers to cause a denial of service via a large number of requests to the login page.

4.3 Medium

CVSS2