A vulnerability was found in Openstack Glance. No limits are enforced within the Glance image service for both v1 and v2 `/images` API POST method for authenticated users, resulting in possible denial of service attacks through database table saturation.
References
Link | Resource |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8611 | Issue Tracking Third Party Advisory |
http://seclists.org/oss-sec/2016/q4/266 | Mailing List Third Party Advisory |
https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-c05333384 | Vendor Advisory |
http://www.securitytracker.com/id/1037312 | Third Party Advisory VDB Entry |
http://www.securityfocus.com/bid/94378 | Third Party Advisory VDB Entry |
Configurations
Information
Published : 2018-07-31 13:29
Updated : 2023-02-12 15:25
NVD link : CVE-2016-8611
Mitre link : CVE-2016-8611
JSON object : View
CWE
CWE-400
Uncontrolled Resource Consumption
Products Affected
openstack
- glance