5
CVSSv2

CVE-2014-8124

Published: 12/12/2014 Updated: 13/02/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

OpenStack Dashboard (Horizon) prior to 2014.1.3 and 2014.2.x prior to 2014.2.1 does not properly handle session records when using a db or memcached session engine, which allows remote malicious users to cause a denial of service via a large number of requests to the login page.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

openstack horizon

fedoraproject fedora 21

opensuse opensuse 13.1

oracle solaris 11.2

Vendor Advisories

Debian Bug report logs - #772710 CVE-2014-8124: Horizon denial of service attack through login page Package: horizon; Maintainer for horizon is Debian OpenStack <team+openstack@trackerdebianorg>; Reported by: Thomas Goirand <zigo@debianorg> Date: Wed, 10 Dec 2014 11:39:08 UTC Severity: important Tags: patch, secur ...