Jump to: navigation, search

Difference between revisions of "OSSN/OSSN-0008"

(Contacts / References)
(Summary)
Line 2: Line 2:
  
 
=== Summary ===
 
=== Summary ===
 +
Currently, there is no limiting on the number of VNC sessions that can be created for a single user's VNC token which enables one to cause a DoS attack on noVNC browser proxy by requesting multiple server. This prevents subsequent access to VM's VNC console.
  
 
=== Affected Services / Software ===
 
=== Affected Services / Software ===

Revision as of 05:06, 19 December 2013

DoS style attack on noVNC server can lead to service interruption or disruption [WIP]

Summary

Currently, there is no limiting on the number of VNC sessions that can be created for a single user's VNC token which enables one to cause a DoS attack on noVNC browser proxy by requesting multiple server. This prevents subsequent access to VM's VNC console.

Affected Services / Software

Horizon, Nova, Grizzly

Discussion

Recommended Actions

Contacts / References