5.3 MEDIUM
- CVSS version: 3.1
- Attack vector (AV): NETWORK
- Attack complexity (AC): LOW
- Privileges required (PR): NONE
- User interaction (UI): NONE
- Scope (S): UNCHANGED
- Confidentiality impact (C): NONE
- Integrity impact (I): NONE
- Availability impact (A): LOW
by @LeSuisse Activity log
- Created suggestion
- @LeSuisse dismissed (not in Nixpkgs)
An issue was discovered in OpenStack Horizon 25.6 and 25.7 …
An issue was discovered in OpenStack Horizon 25.6 and 25.7 before 25.7.3. There is a write operation to the session storage backend before authentication and thus storage can be exhausted by unauthenticated requests. This is a regression of the CVE-2014-8124 fix.
References
Affected products
- <25.7.3
Matching in nixpkgs
pkgs.horizon-eda
Free EDA software to develop printed circuit boards
pkgs.omnissa-horizon-client
Allows you to connect to your Omnissa Horizon virtual desktop
pkgs.python312Packages.horizon-eda
Free EDA software to develop printed circuit boards
pkgs.python313Packages.horizon-eda
Free EDA software to develop printed circuit boards
pkgs.python314Packages.horizon-eda
Free EDA software to develop printed circuit boards
pkgs.haskellPackages.horizontal-rule
horizontal rule for the terminal
pkgs.haskellPackages.jpl-horizons-api
Ephemerides for solar system objects from the JPL Horizons service
pkgs.gnomeExtensions.status-area-horizontal-spacing
Reduce the horizontal spacing between icons in the top-right status area
pkgs.home-assistant-custom-lovelace-modules.horizon-card
Sun Card successor: Visualize the position of the Sun over the horizon
Package maintainers
-
@honnip Jung seungwoo <me@honnip.page>
-
@SuperSandro2000 Sandro Jäckel <sandro.jaeckel@gmail.com>
-
@guserav guserav
-
@mhutter Manuel Hutter <manuel@hutter.io>