HIGH 7.5 PyPI

OpenStack Identity (Keystone) DoS through V3 API authentication chaining

GHSA-6mv3-p2gr-wgqf · CVE-2014-2828 · PYSEC-2014-106

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

The V3 API in OpenStack Identity (Keystone) 2013.1 before 2013.2.4 and icehouse before icehouse-rc2 allows remote attackers to cause a denial of service (CPU consumption) via a large number of the same authentication method in a request, aka "authentication chaining."

Ready to move

Start Securing

Free, no credit card | First findings in minutes