CVE-2014-8124
published 2014-12-12CVE-2014-8124: OpenStack Dashboard (Horizon) before 2014.1.3 and 2014.2.x before 2014.2.1 does not properly handle session records when using a db or memcached session…
PriorityP422medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
2.86%
85.2th percentile
OpenStack Dashboard (Horizon) before 2014.1.3 and 2014.2.x before 2014.2.1 does not properly handle session records when using a db or memcached session engine, which allows remote attackers to cause a denial of service via a large number of requests to the login page.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | horizon | < horizon 2014.1.3-6 (bookworm) | horizon 2014.1.3-6 (bookworm) |
| fedoraproject | fedora | — | — |
| openstack | horizon | >= 0 < 2014.1.3-6 | 2014.1.3-6 |
| openstack | horizon | >= 0 < 2014.1.3-6 | 2014.1.3-6 |
| openstack | horizon | >= 0 < 2014.1.3-6 | 2014.1.3-6 |
| openstack | horizon | >= 0 < 2014.1.3-6 | 2014.1.3-6 |
| openstack | horizon | >= 2014.1 < 2014.1.3 | 2014.1.3 |
| openstack | horizon | >= 2014.2.0 < 2014.2.1 | 2014.2.1 |
| openstack | horizon | >= 25.6.0 < 25.7.3 | 25.7.3 |
| opensuse | opensuse | — | — |
| oracle | solaris | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
ghsa5.0MEDIUM
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
python-django-horizon: denial of service via login page requests
vendor_redhat·2014-12-09·CVSS 5.0
CVE-2014-8124 [MEDIUM] CWE-400 python-django-horizon: denial of service via login page requests
python-django-horizon: denial of service via login page requests
OpenStack Dashboard (Horizon) before 2014.1.3 and 2014.2.x before 2014.2.1 does not properly handle session records when using a db or memcached session engine, which allows remote attackers to cause a denial of service via a large number of requests to the login page.
A denial of service flaw was found in the OpenStack Dashboard (horizon) when using the db or memcached session engine. An attacker could make repeated requests to the login page, which would result in a large number of unwanted backend session entries, possibly leading to a denial of service.
Package: python-django-horizon (Red Hat Enterprise Linux OpenStack Platform 6 (Juno)) - Not affected
Package: python-django-openstack-auth (Red Hat Enterprise Linux Op
Debian
CVE-2014-8124: horizon - OpenStack Dashboard (Horizon) before 2014.1.3 and 2014.2.x before 2014.2.1 does ...
vendor_debian·2014·CVSS 5.0
CVE-2014-8124 [MEDIUM] CVE-2014-8124: horizon - OpenStack Dashboard (Horizon) before 2014.1.3 and 2014.2.x before 2014.2.1 does ...
OpenStack Dashboard (Horizon) before 2014.1.3 and 2014.2.x before 2014.2.1 does not properly handle session records when using a db or memcached session engine, which allows remote attackers to cause a denial of service via a large number of requests to the login page.
Scope: local
bookworm: resolved (fixed in 2014.1.3-6)
bullseye: resolved (fixed in 2014.1.3-6)
forky: resolved (fixed in 2014.1.3-6)
sid: resolved (fixed in 2014.1.3-6)
trixie: resolved (fixed in 2014.1.3-6)
GHSA
GHSA-vxvf-xvm3-p8j5: An issue was discovered in OpenStack Horizon 25
ghsa_unreviewed·2026-05-05·CVSS 5.0
CVE-2026-43002 [MEDIUM] CWE-696 GHSA-vxvf-xvm3-p8j5: An issue was discovered in OpenStack Horizon 25
An issue was discovered in OpenStack Horizon 25.6 and 25.7 before 25.7.3. There is a write operation to the session storage backend before authentication and thus storage can be exhausted by unauthenticated requests. This is a regression of the CVE-2014-8124 fix.
GHSA
OpenStack Horizon has Incorrect Behavior Order
ghsa·2026-05-05·CVSS 5.0
CVE-2026-43002 [MEDIUM] CWE-696 OpenStack Horizon has Incorrect Behavior Order
OpenStack Horizon has Incorrect Behavior Order
An issue was discovered in OpenStack Horizon 25.6 and 25.7 before 25.7.3. There is a write operation to the session storage backend before authentication and thus storage can be exhausted by unauthenticated requests. This is a regression of the CVE-2014-8124 fix.
GHSA
GHSA-q878-vxpg-6qx6: OpenStack Dashboard (Horizon) before 2014
ghsa_unreviewed·2022-05-13
CVE-2014-8124 [MEDIUM] CWE-400 GHSA-q878-vxpg-6qx6: OpenStack Dashboard (Horizon) before 2014
OpenStack Dashboard (Horizon) before 2014.1.3 and 2014.2.x before 2014.2.1 does not properly handle session records when using a db or memcached session engine, which allows remote attackers to cause a denial of service via a large number of requests to the login page.
OSV
CVE-2014-8124: OpenStack Dashboard (Horizon) before 2014
osv·2014-12-12·CVSS 5.0
CVE-2014-8124 [MEDIUM] CVE-2014-8124: OpenStack Dashboard (Horizon) before 2014
OpenStack Dashboard (Horizon) before 2014.1.3 and 2014.2.x before 2014.2.1 does not properly handle session records when using a db or memcached session engine, which allows remote attackers to cause a denial of service via a large number of requests to the login page.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-8124 python-django-horizon: denial of service via login page requests [fedora-all]
bugzilla·2014-12-15·CVSS 5.0
CVE-2014-8124 [MEDIUM] CVE-2014-8124 python-django-horizon: denial of service via login page requests [fedora-all]
CVE-2014-8124 python-django-horizon: denial of service via login page requests [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supporte
Bugzilla
CVE-2014-8124 python-django-horizon: denial of service via login page requests
bugzilla·2014-12-02·CVSS 5.0
CVE-2014-8124 [MEDIUM] CVE-2014-8124 python-django-horizon: denial of service via login page requests
CVE-2014-8124 python-django-horizon: denial of service via login page requests
The OpenStack project reports:
""
Title: Horizon denial of service attack through login page
Reporter: Eric Peterson (Time Warner Cable)
Products: Horizon
Versions: up to 2014.1.3, and 2014.2 versions up to 2014.2.1
Description:
Eric Peterson from Time Warner Cable reported a vulnerability in
Horizon. By making repeated requests to the Horizon login page a remote
attacker may generate unwanted session records, potentially resulting in
a denial of service. Only Horizon setups using a db or memcached session
engine are affected.
""
Discussion:
Created attachment 964402
cve-2014-8124-django_openstack_auth.patch
---
Created attachment 964403
cve-2014-8124-master-kilo.patch
---
Created attachment 964404
cve-
http://lists.fedoraproject.org/pipermail/package-announce/2015-January/147520.htmlhttp://lists.openstack.org/pipermail/openstack-announce/2014-December/000308.htmlhttp://lists.opensuse.org/opensuse-updates/2015-01/msg00040.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0839.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0845.htmlhttp://secunia.com/advisories/61186http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.htmlhttps://bugs.launchpad.net/horizon/+bug/1394370http://lists.fedoraproject.org/pipermail/package-announce/2015-January/147520.htmlhttp://lists.openstack.org/pipermail/openstack-announce/2014-December/000308.htmlhttp://lists.opensuse.org/opensuse-updates/2015-01/msg00040.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0839.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0845.htmlhttp://secunia.com/advisories/61186http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.htmlhttps://bugs.launchpad.net/horizon/+bug/1394370
2014-12-12
Published