CVE-2014-8124

OpenStack Dashboard (Horizon) before 2014.1.3 and 2014.2.x before 2014.2.1 does not properly handle session records when using a db or memcached session engine, which allows remote attackers to cause a denial of service via a large number of requests to the login page.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:openstack:horizon:*:*:*:*:*:*:*:*
cpe:2.3:a:openstack:horizon:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:fedoraproject:fedora:21:*:*:*:*:*:*:*

Configuration 3 (hide)

cpe:2.3:o:opensuse:opensuse:13.1:*:*:*:*:*:*:*

Configuration 4 (hide)

cpe:2.3:o:oracle:solaris:11.2:*:*:*:*:*:*:*

History

13 Feb 2023, 00:43

Type Values Removed Values Added
References
  • {'url': 'https://access.redhat.com/errata/RHSA-2015:0839', 'name': 'https://access.redhat.com/errata/RHSA-2015:0839', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://bugzilla.redhat.com/show_bug.cgi?id=1169637', 'name': 'https://bugzilla.redhat.com/show_bug.cgi?id=1169637', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://access.redhat.com/security/cve/CVE-2014-8124', 'name': 'https://access.redhat.com/security/cve/CVE-2014-8124', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://access.redhat.com/errata/RHSA-2015:0845', 'name': 'https://access.redhat.com/errata/RHSA-2015:0845', 'tags': [], 'refsource': 'MISC'}
Summary A denial of service flaw was found in the OpenStack Dashboard (horizon) when using the db or memcached session engine. An attacker could make repeated requests to the login page, which would result in a large number of unwanted backend session entries, possibly leading to a denial of service. OpenStack Dashboard (Horizon) before 2014.1.3 and 2014.2.x before 2014.2.1 does not properly handle session records when using a db or memcached session engine, which allows remote attackers to cause a denial of service via a large number of requests to the login page.

02 Feb 2023, 20:19

Type Values Removed Values Added
References
  • (MISC) https://access.redhat.com/errata/RHSA-2015:0839 -
  • (MISC) https://bugzilla.redhat.com/show_bug.cgi?id=1169637 -
  • (MISC) https://access.redhat.com/security/cve/CVE-2014-8124 -
  • (MISC) https://access.redhat.com/errata/RHSA-2015:0845 -
Summary OpenStack Dashboard (Horizon) before 2014.1.3 and 2014.2.x before 2014.2.1 does not properly handle session records when using a db or memcached session engine, which allows remote attackers to cause a denial of service via a large number of requests to the login page. A denial of service flaw was found in the OpenStack Dashboard (horizon) when using the db or memcached session engine. An attacker could make repeated requests to the login page, which would result in a large number of unwanted backend session entries, possibly leading to a denial of service.

09 Mar 2021, 15:06

Type Values Removed Values Added
References (REDHAT) http://rhn.redhat.com/errata/RHSA-2015-0839.html - Third Party Advisory (REDHAT) http://rhn.redhat.com/errata/RHSA-2015-0839.html - Broken Link
References (REDHAT) http://rhn.redhat.com/errata/RHSA-2015-0845.html - Third Party Advisory (REDHAT) http://rhn.redhat.com/errata/RHSA-2015-0845.html - Broken Link
References (SUSE) http://lists.opensuse.org/opensuse-updates/2015-01/msg00040.html - Third Party Advisory (SUSE) http://lists.opensuse.org/opensuse-updates/2015-01/msg00040.html - Mailing List, Third Party Advisory
References (CONFIRM) https://bugs.launchpad.net/horizon/+bug/1394370 - Issue Tracking (CONFIRM) https://bugs.launchpad.net/horizon/+bug/1394370 - Issue Tracking, Third Party Advisory
References (SECUNIA) http://secunia.com/advisories/61186 - Permissions Required, Third Party Advisory (SECUNIA) http://secunia.com/advisories/61186 - Third Party Advisory
References (CONFIRM) http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.html - (CONFIRM) http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.html - Third Party Advisory
CPE cpe:2.3:a:openstack:horizon:2014.2.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openstack:5.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:oracle:solaris:11.2:*:*:*:*:*:*:*
CWE CWE-399 CWE-400
CVSS v2 : 4.3
v3 : unknown
v2 : 5.0
v3 : unknown

Information

Published : 2014-12-12 15:59

Updated : 2023-12-10 11:31


NVD link : CVE-2014-8124

Mitre link : CVE-2014-8124

CVE.ORG link : CVE-2014-8124


JSON object : View

Products Affected

fedoraproject

  • fedora

opensuse

  • opensuse

openstack

  • horizon

oracle

  • solaris
CWE
CWE-400

Uncontrolled Resource Consumption