python-django-horizon: denial of service via login page requests
Published Dec 12, 2014
5.0
MEDIUMCVSS 2.0
EPSS 2.86%
Description
OpenStack Dashboard (Horizon) before 2014.1.3 and 2014.2.x before 2014.2.1 does not properly handle session records when using a db or memcached session engine, which allows remote attackers to cause a denial of service via a large number of requests to the login page.
Affected products
No data.
No data.
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6
python-django-horizon-0:2014.1.4-1.el6ost
Fixed · RHSA-2015:0845
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6
python-django-openstack-auth-0:1.1.5-4.el6ost
Fixed · RHSA-2015:0845
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7
python-django-horizon-0:2014.1.4-1.el7ost
Fixed · RHSA-2015:0839
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7
python-django-openstack-auth-0:1.1.5-4.el7ost
Fixed · RHSA-2015:0839
Red Hat Enterprise Linux OpenStack Platform 6 (Juno)
python-django-horizon
Not affected
Red Hat Enterprise Linux OpenStack Platform 6 (Juno)
python-django-openstack-auth
Not affected
Red Hat OpenStack Platform 4
python-django-horizon
Will not fix
Red Hat OpenStack Platform 4
python-django-openstack-auth
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6 | python-django-horizon-0:2014.1.4-1.el6ost | Fixed | RHSA-2015:0845 |
| Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6 | python-django-openstack-auth-0:1.1.5-4.el6ost | Fixed | RHSA-2015:0845 |
| Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7 | python-django-horizon-0:2014.1.4-1.el7ost | Fixed | RHSA-2015:0839 |
| Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7 | python-django-openstack-auth-0:1.1.5-4.el7ost | Fixed | RHSA-2015:0839 |
| Red Hat Enterprise Linux OpenStack Platform 6 (Juno) | python-django-horizon | Not affected | n/a |
| Red Hat Enterprise Linux OpenStack Platform 6 (Juno) | python-django-openstack-auth | Not affected | n/a |
| Red Hat OpenStack Platform 4 | python-django-horizon | Will not fix | n/a |
| Red Hat OpenStack Platform 4 | python-django-openstack-auth | Will not fix | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:N/I:N/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (14 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 2.86% (0.02864) | 86.28th | v5 (v2026.06.15) |
| Jun 15, 2026 | 2.84% (0.02841) | 84.78th | v5 (v2026.06.15) |
| Mar 30, 2025 | 0.97% (0.00970) | 74.58th | v4 (v2025.03.14) |
| Mar 29, 2025 | 2.40% (0.02404) | 75.08th | v4 (v2025.03.14) |
| Mar 17, 2025 | 0.97% (0.00970) | 75.05th | v4 (v2025.03.14) |
| Dec 17, 2024 | 2.78% (0.02779) | 90.33th | v3 (v2023.03.01) |
| Dec 12, 2024 | 1.57% (0.01568) | 87.76th | v3 (v2023.03.01) |
| Jun 7, 2024 | 1.77% (0.01774) | 88.05th | v3 (v2023.03.01) |
| Mar 7, 2023 | 1.76% (0.01762) | 86.02th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.41% (0.01408) | 72.89th | v2 (v2022.01.01) |
| Feb 13, 2023 | 1.41% (0.01408) | 72.37th | v2 (v2022.01.01) |
| Feb 3, 2023 | 1.54% (0.01537) | 73.85th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.41% (0.01408) | 70.87th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.41% (0.01408) | 49.94th | v2 (v2022.01.01) |
References (12)
- http://lists.fedoraproject.org/pipermail/package-announce/2015-January/147520.html vendor-advisoryx_refsource_FEDORAThird Party Advisory
- http://lists.openstack.org/pipermail/openstack-announce/2014-December/000308.html mailing-listx_refsource_MLISTPatchVendor Advisory
- http://lists.opensuse.org/opensuse-updates/2015-01/msg00040.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-0839.html vendor-advisoryx_refsource_REDHATBroken Link
- http://rhn.redhat.com/errata/RHSA-2015-0845.html vendor-advisoryx_refsource_REDHATBroken Link
- http://secunia.com/advisories/61186 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.html x_refsource_CONFIRMThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2014-8124 Vendor Advisory
- https://bugs.launchpad.net/horizon/+bug/1394370 x_refsource_CONFIRMIssue TrackingThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1169637 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2014-8124
- https://www.cve.org/CVERecord?id=CVE-2014-8124
Change history (0)
No recorded changes yet.