Comment 42 for bug 1394370

Revision history for this message
Tristan Cacqueray (tristan-cacqueray) wrote : Re: horizon login page is vulnerable to DOS attack

@Eric thanks for the clarification!

Here is the updated impact description draft #3 (including the session engine impact):

Title: Horizon denial of service attack through login page
Reporter: Eric Peterson (Time Warner Cable)
Products: Horizon
Versions: up to 2014.1.3 and 2014.2

Description:
Eric Peterson from Time Warner Cable reported a vulnerability in Horizon. By doing repeated requests to Horizon login page a remote attacker may generate unwanted session record, potentially resulting in a denial of service. Only Horizon setups using a db or memcached session engine are affected.