Openstack · Openstack Image Registry/Delivery Service · CVE-2015-1881
**Name of the Vulnerable Software and Affected Versions**
OpenStack Image Registry and Delivery Service (Glance) versions 2014.2 through 2014.2.2
**Description**
The issue allows remote authenticated users to cause a denial of service, specifically disk consumption, by creating and then deleting a large number of images using the task v2 API.
**Recommendations**
For versions 2014.2 through 2014.2.2, consider restricting access to the task v2 API to prevent excessive image creation and deletion.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.