Jump to: navigation, search

OSSN/OSSN-0008

< OSSN
Revision as of 05:06, 19 December 2013 by Sriramhere (talk | contribs) (Summary)

DoS style attack on noVNC server can lead to service interruption or disruption [WIP]

Summary

Currently, there is no limiting on the number of VNC sessions that can be created for a single user's VNC token which enables one to cause a DoS attack on noVNC browser proxy by requesting multiple server. This prevents subsequent access to VM's VNC console.

Affected Services / Software

Horizon, Nova, Grizzly

Discussion

Recommended Actions

Contacts / References