7.8
CVSSv2

CVE-2014-2828

Published: 15/04/2014 Updated: 04/11/2015
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
VMScore: 694
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

The V3 API in OpenStack Identity (Keystone) 2013.1 prior to 2013.2.4 and icehouse before icehouse-rc2 allows remote malicious users to cause a denial of service (CPU consumption) via a large number of the same authentication method in a request, aka "authentication chaining."

Vulnerable Product Search on Vulmon Subscribe to Product

openstack keystone 2013.1.2

openstack keystone 2013.2

openstack keystone 2013.2.3

openstack keystone 2013.2.2

openstack keystone 2013.1.1

openstack keystone 2013.1

openstack keystone 2013.1.3

openstack keystone 2013.2.1