OpenStack Image Service (Glance) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) allows remote authenticated users to bypass the storage quota and cause a denial of service (disk consumption) by deleting images that are being uploaded using a token that expires during the process. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-9623.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Image_registry_and_delivery_service_(glance) | Openstack | * | 2014.2.3 (including) |
Image_registry_and_delivery_service_(glance) | Openstack | 2015.1.0 (including) | 2015.1.0 (including) |
Image_registry_and_delivery_service_(glance) | Openstack | 2015.1.1 (including) | 2015.1.1 (including) |
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6 | RedHat | openstack-glance-0:2014.1.5-3.el6ost | * |
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7 | RedHat | openstack-glance-0:2014.1.5-3.el7ost | * |
Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7 | RedHat | openstack-glance-0:2014.2.3-3.el7ost | * |
Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7 | RedHat | openstack-glance-0:2015.1.1-3.el7ost | * |
Glance | Ubuntu | precise | * |
Glance | Ubuntu | trusty | * |