CVE Vulnerabilities

CVE-2015-5286

Published: Oct 26, 2015 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.8 MEDIUM
AV:N/AC:L/Au:S/C:N/I:N/A:C
RedHat/V2
5 MODERATE
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

OpenStack Image Service (Glance) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) allows remote authenticated users to bypass the storage quota and cause a denial of service (disk consumption) by deleting images that are being uploaded using a token that expires during the process. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-9623.

Affected Software

NameVendorStart VersionEnd Version
Image_registry_and_delivery_service_(glance)Openstack*2014.2.3 (including)
Image_registry_and_delivery_service_(glance)Openstack2015.1.0 (including)2015.1.0 (including)
Image_registry_and_delivery_service_(glance)Openstack2015.1.1 (including)2015.1.1 (including)
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6RedHatopenstack-glance-0:2014.1.5-3.el6ost*
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7RedHatopenstack-glance-0:2014.1.5-3.el7ost*
Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7RedHatopenstack-glance-0:2014.2.3-3.el7ost*
Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7RedHatopenstack-glance-0:2015.1.1-3.el7ost*
GlanceUbuntuprecise*
GlanceUbuntutrusty*

References