CVE-2014-2828: High severity Openstack Keystone vulnerability
The V3 API in OpenStack Identity (Keystone) 2013.1 before 2013.2.4 and icehouse before icehouse-rc2 allows remote attackers to cause a denial of service (CPU consumption) via a large number of the same authentication method in a request, aka "authentication chaining."
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/keystoneto a version that resolves this vulnerability.Fixed in 8.0.0a0
Event History
Frequently Asked Questions
What is the severity of CVE-2014-2828?
CVE-2014-2828 is considered a denial of service vulnerability, as it allows remote attackers to cause CPU consumption.
How do I fix CVE-2014-2828?
To fix CVE-2014-2828, upgrade to Keystone version 2013.2.4 or later.
Which versions of OpenStack Keystone are affected by CVE-2014-2828?
CVE-2014-2828 affects OpenStack Keystone versions 2013.1 up to 2013.2.3.
Can CVE-2014-2828 be exploited remotely?
Yes, CVE-2014-2828 can be exploited remotely by sending a large number of the same authentication methods in a request.
What type of attack does CVE-2014-2828 involve?
CVE-2014-2828 involves an authentication chaining attack that leads to denial of service.