PT-2015-4312 · Openstack · Openstack Glance

Tushar Patil

·

Published

2015-01-23

·

Updated

2022-05-17

·

CVE-2014-9623

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions OpenStack Glance versions 2014.2.x through 2014.2.1 OpenStack Glance version 2014.1.3 and earlier
Description The issue allows remote authenticated users to bypass the storage quota, causing a denial of service due to disk consumption. This occurs when an image in the saving state is deleted.
Recommendations For OpenStack Glance versions 2014.2.x through 2014.2.1, update to a version that fixes the quota bypass issue to prevent denial of service. For OpenStack Glance version 2014.1.3 and earlier, update to a version that fixes the quota bypass issue to prevent denial of service. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-9623
GHSA-J4MH-9WQ6-8RG6
RHSA-2015:0644
RHSA-2015:0837
RHSA-2015:0838

Affected Products

Openstack Glance