Bug 908199 (CVE-2014-8124) - VUL-0: CVE-2014-8124: openstack-dashboard: Horizon denial of service attack through login page
Summary: VUL-0: CVE-2014-8124: openstack-dashboard: Horizon denial of service attack t...
Status: RESOLVED FIXED
Alias: CVE-2014-8124
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Deadline: 2015-06-19
Assignee: Security Team bot
QA Contact: Security Team bot
URL:
Whiteboard: maint:released:sle11-sp3-cl4:60012 ma...
Keywords:
Depends on:
Blocks:
 
Reported: 2014-12-03 15:45 UTC by Alexander Bergmann
Modified: 2015-07-02 17:01 UTC (History)
4 users (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Alexander Bergmann 2014-12-03 15:45:02 UTC
CRD: 2014-12-09 15:00 UTC

This is an advance warning of a vulnerability discovered in OpenStack,
to give you, as downstream stakeholders, a chance to coordinate the
release of fixes and reduce the vulnerability window. Please treat the
following information as confidential until the proposed public
disclosure date.

Title: Horizon denial of service attack through login page
Reporter: Eric Peterson (Time Warner Cable)
Products: Horizon
Versions: up to 2014.1.3, and 2014.2 versions up to 2014.2.1

Description:
Eric Peterson from Time Warner Cable reported a vulnerability in
Horizon. By making repeated requests to the Horizon login page a remote
attacker may generate unwanted session records, potentially resulting in
a denial of service. Only Horizon setups using a db or memcached session
engine are affected.

Proposed patch:
See attached patches. Unless a flaw is discovered in them, these patches
will be merged to stable/icehouse, stable/juno and master on the public
disclosure date. Note that the django_openstack_auth Horizon dependency
requires an additional patch to be applied.

CVE: CVE-2014-8124

Proposed public disclosure date/time:
2014-12-09, 1500UTC
Please do not make the issue public (or release public patches) before
this coordinated embargo date.
Comment 1 Alexander Bergmann 2014-12-03 15:45:43 UTC
Created attachment 615774 [details]
cve-2014-8124-stable-icehouse.patch
Comment 2 Alexander Bergmann 2014-12-03 15:45:59 UTC
Created attachment 615775 [details]
cve-2014-8124-master-kilo.patch
Comment 3 Alexander Bergmann 2014-12-03 15:46:23 UTC
Created attachment 615776 [details]
cve-2014-8124-stable-juno.patch
Comment 4 Alexander Bergmann 2014-12-03 15:46:42 UTC
Created attachment 615777 [details]
cve-2014-8124-django_openstack_auth.patch
Comment 5 Swamp Workflow Management 2014-12-03 23:00:22 UTC
bugbot adjusting priority
Comment 6 Swamp Workflow Management 2014-12-04 20:30:27 UTC
An update workflow for this issue was started.
This issue was rated as moderate.
Please submit fixed packages until 2014-12-18.
When done, reassign the bug to security-team@suse.de.
https://swamp.suse.de/webswamp/wf/59957
Comment 8 Johannes Segitz 2014-12-10 08:16:04 UTC
public
Comment 11 Bernhard Wiedemann 2014-12-12 14:00:43 UTC
This is an autogenerated message for OBS integration:
This bug (908199) was mentioned in
https://build.opensuse.org/request/show/265000 13.1 / openstack-dashboard
Comment 13 Bernhard Wiedemann 2014-12-15 13:28:31 UTC
updates submitted to Cloud3, Cloud4 and 13.1 .
13.2 and Factory do not have OpenStack
and 12.3 has an OpenStack EOL version
Comment 15 Swamp Workflow Management 2015-01-07 20:04:50 UTC
SUSE-SU-2015:0015-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 908199
CVE References: CVE-2014-8124
Sources used:
SUSE Cloud 4 (src):    openstack-dashboard-2014.1.4.dev12.gfb429f4-0.7.1
Comment 16 Victor Pereira 2015-01-09 12:39:01 UTC
released
Comment 17 Swamp Workflow Management 2015-01-19 13:06:09 UTC
openSUSE-SU-2015:0078-1: An update that fixes 7 vulnerabilities is now available.

Category: security (moderate)
Bug References: 852175,869696,871855,885588,891815,908199
CVE References: CVE-2013-6858,CVE-2014-0157,CVE-2014-3473,CVE-2014-3474,CVE-2014-3475,CVE-2014-3594,CVE-2014-8124
Sources used:
openSUSE 13.1 (src):    openstack-dashboard-2013.2.5.dev2.g9ee7273-4.1, python-django_openstack_auth-1.1.3-4.1
Comment 18 Swamp Workflow Management 2015-06-05 13:05:09 UTC
An update workflow for this issue was started.
This issue was rated as moderate.
Please submit fixed packages until 2015-06-19.
When done, reassign the bug to security-team@suse.de.
https://swamp.suse.de/webswamp/wf/61888