7.8

CVE-2014-2828

The V3 API in OpenStack Identity (Keystone) 2013.1 before 2013.2.4 and icehouse before icehouse-rc2 allows remote attackers to cause a denial of service (CPU consumption) via a large number of the same authentication method in a request, aka "authentication chaining."
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Openstack ≫ Keystone Version 2013.1
Openstack ≫ Keystone Version 2013.1.1
Openstack ≫ Keystone Version 2013.1.2
Openstack ≫ Keystone Version 2013.1.3
Openstack ≫ Keystone Version 2013.2
Openstack ≫ Keystone Version 2013.2.1
Openstack ≫ Keystone Version 2013.2.2
Openstack ≫ Keystone Version 2013.2.3
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.16% 0.864
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 10 6.9
AV:N/AC:L/Au:N/C:N/I:N/A:C
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

http://rhn.redhat.com/errata/RHSA-2014-1688.html
http://www.openwall.com/lists/oss-security/2014/04/10/20
https://bugs.launchpad.net/keystone/+bug/1300274