CVE-2014-8124: Medium severity Openstack Horizon vulnerability
OpenStack Dashboard (Horizon) before 2014.1.3 and 2014.2.x before 2014.2.1 does not properly handle session records when using a db or memcached session engine, which allows remote attackers to cause a denial of service via a large number of requests to the login page.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2014-8124?
CVE-2014-8124 has a high severity level due to its potential to cause a denial of service through excessive login requests.
How do I fix CVE-2014-8124?
To fix CVE-2014-8124, upgrade to OpenStack Horizon version 2014.1.3 or later, or 2014.2.1 or later.
What types of session engines are affected by CVE-2014-8124?
CVE-2014-8124 affects the database and memcached session engines used by OpenStack Horizon.
What can attackers achieve by exploiting CVE-2014-8124?
By exploiting CVE-2014-8124, attackers can cause a denial of service by overwhelming the login page with numerous requests.
Which versions of OpenStack Horizon are vulnerable to CVE-2014-8124?
OpenStack Horizon versions before 2014.1.3 and 2014.2.0 up to but not including 2014.2.1 are vulnerable to CVE-2014-8124.