OpenStack Image Service (Glance) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) allows remote authenticated users to bypass the storage quota and cause a denial of service (disk consumption) by deleting images that are being uploaded using a token that expires during the process. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-9623.
References
Configurations
Configuration 1 (hide)
|
History
07 Nov 2023, 02:26
Type | Values Removed | Values Added |
---|---|---|
Summary | OpenStack Image Service (Glance) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) allows remote authenticated users to bypass the storage quota and cause a denial of service (disk consumption) by deleting images that are being uploaded using a token that expires during the process. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-9623. |
12 Feb 2023, 23:15
Type | Values Removed | Values Added |
---|---|---|
Summary | OpenStack Image Service (Glance) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) allows remote authenticated users to bypass the storage quota and cause a denial of service (disk consumption) by deleting images that are being uploaded using a token that expires during the process. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-9623. | |
References |
|
02 Feb 2023, 21:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
Summary | A race-condition flaw was discovered in the OpenStack Image service (glance). When images in the upload state were deleted using a token close to expiration, untracked image data could accumulate in the back end. Because untracked data does not count towards the storage quota, an attacker could use this flaw to cause a denial of service through resource exhaustion. |
Information
Published : 2015-10-26 17:59
Updated : 2023-12-10 11:46
NVD link : CVE-2015-5286
Mitre link : CVE-2015-5286
CVE.ORG link : CVE-2015-5286
JSON object : View
Products Affected
openstack
- image_registry_and_delivery_service_\(glance\)
CWE
CWE-264
Permissions, Privileges, and Access Controls