OpenStack Glance 2014.2.x through 2014.2.1, 2014.1.3, and earlier allows remote authenticated users to bypass the storage quota and cause a denial of service (disk consumption) by deleting an image in the saving state.
2015-01-23T15:59:06.537
2025-04-12T10:46:40.837
Deferred
CVSSv2: 4.0 (MEDIUM)
AV:N/AC:L/Au:S/C:N/I:N/A:P
8.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | redhat | openstack | 5.0 | Yes |
Application | openstack | image_registry_and_delivery_service_\(glance\) | ≤ 2014.1.3 | Yes |
Application | openstack | image_registry_and_delivery_service_\(glance\) | 2014.2 | Yes |
Application | openstack | image_registry_and_delivery_service_\(glance\) | 2014.2 | Yes |
Application | openstack | image_registry_and_delivery_service_\(glance\) | 2014.2 | Yes |
Application | openstack | image_registry_and_delivery_service_\(glance\) | 2014.2 | Yes |