Description
The V3 API in OpenStack Identity (Keystone) 2013.1 before 2013.2.4 and icehouse before icehouse-rc2 allows remote attackers to cause a denial of service (CPU consumption) via a large number of the same authentication method in a request, aka "authentication chaining."
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2014-0026 | The V3 API in OpenStack Identity (Keystone) 2013.1 before 2013.2.4 and icehouse before icehouse-rc2 allows remote attackers to cause a denial of service (CPU consumption) via a large number of the same authentication method in a request, aka \"authentication chaining.\" |
Github GHSA |
GHSA-6mv3-p2gr-wgqf | OpenStack Identity (Keystone) DoS through V3 API authentication chaining |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-06T10:28:45.404Z
Reserved: 2014-04-10T00:00:00.000Z
Link: CVE-2014-2828
No data.
Status : Modified
Published: 2014-04-15T14:55:04.857
Modified: 2026-05-06T22:30:45.220
Link: CVE-2014-2828
OpenCVE Enrichment
No data.
EUVD
Github GHSA