OpenStack Horizon Login Page Denial of Service Vulnerability
BID:71648
Info
OpenStack Horizon Login Page Denial of Service Vulnerability
| Bugtraq ID: | 71648 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2014-8124 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 19 2014 12:00AM |
| Updated: | May 12 2015 07:47PM |
| Credit: | Eric Peterson |
| Vulnerable: |
Redhat Enterprise Linux OpenStack Platform for RHEL 7 5.0 Redhat Enterprise Linux OpenStack Platform for RHEL 6 5.0 OpenStack Horizon 2014.2.1 OpenStack Horizon 2014.1.3 OpenStack Horizon 2014.1.1 OpenStack Horizon 2013.2.4 OpenStack Horizon 2014.2 OpenStack Horizon 2014.1.2 OpenStack Horizon 2014.1 OpenStack Horizon 2013.2.3 OpenStack Horizon 2013.2.2 OpenStack Horizon 2013.2.1 OpenStack Horizon 2013.2 OpenStack Horizon 2013.1 |
| Not Vulnerable: | |
Discussion
OpenStack Horizon Login Page Denial of Service Vulnerability
OpenStack Horizon is prone to a denial-of-service vulnerability.
Attackers can exploit this issue to generate unwanted session records resulting in a denial-of service condition.
OpenStack Horizon is prone to a denial-of-service vulnerability.
Attackers can exploit this issue to generate unwanted session records resulting in a denial-of service condition.
Exploit / POC
OpenStack Horizon Login Page Denial of Service Vulnerability
An attacker can exploit this through readily available tools.
An attacker can exploit this through readily available tools.
Solution / Fix
OpenStack Horizon Login Page Denial of Service Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
OpenStack Horizon Login Page Denial of Service Vulnerability
References:
References:
- OpenStack Dashboard (Horizon) Homepage (OpenStack )