OpenStack Glance before 2015.1.1 (kilo) allows remote authenticated users to cause a denial of service (disk consumption) by repeatedly using the import task flow API to create images and then deleting them.
References
Link | Resource |
---|---|
https://bugs.launchpad.net/glance/+bug/1454087 | Patch |
http://lists.openstack.org/pipermail/openstack-announce/2015-July/000481.html | Patch Vendor Advisory |
http://www.securityfocus.com/bid/76068 |
Configurations
Information
Published : 2015-08-14 11:59
Updated : 2016-12-02 19:09
NVD link : CVE-2015-3289
Mitre link : CVE-2015-3289
JSON object : View
CWE
CWE-399
Resource Management Errors
Products Affected
openstack
- glance