Unrated severityNVD Advisory· Published Dec 12, 2014· Updated May 6, 2026
CVE-2014-8124
CVE-2014-8124
Description
OpenStack Dashboard (Horizon) before 2014.1.3 and 2014.2.x before 2014.2.1 does not properly handle session records when using a db or memcached session engine, which allows remote attackers to cause a denial of service via a large number of requests to the login page.
Affected products
4- cpe:2.3:o:fedoraproject:fedora:21:*:*:*:*:*:*:*
- cpe:2.3:o:oracle:solaris:11.2:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
8- lists.openstack.org/pipermail/openstack-announce/2014-December/000308.htmlnvdPatchVendor Advisory
- lists.fedoraproject.org/pipermail/package-announce/2015-January/147520.htmlnvdThird Party Advisory
- lists.opensuse.org/opensuse-updates/2015-01/msg00040.htmlnvdMailing ListThird Party Advisory
- secunia.com/advisories/61186nvdThird Party Advisory
- www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.htmlnvdThird Party Advisory
- bugs.launchpad.net/horizon/+bug/1394370nvdIssue TrackingThird Party Advisory
- rhn.redhat.com/errata/RHSA-2015-0839.htmlnvdBroken Link
- rhn.redhat.com/errata/RHSA-2015-0845.htmlnvdBroken Link
News mentions
0No linked articles in our index yet.