Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4jp4-3c62-r8jv

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 8.7
CVSS3: 7.5

Описание

OpenStack Glance Denial of service by creating a large number of images

OpenStack Image Registry and Delivery Service (Glance) 2014.2 through 2014.2.2 does not properly remove images, which allows remote authenticated users to cause a denial of service (disk consumption) by creating a large number of images using the task v2 API and then deleting them, a different vulnerability than CVE-2014-9684.

Пакеты

Наименование

glance

pip
Затронутые версииВерсия исправления

< 11.0.0a0

11.0.0a0

EPSS

Процентиль: 68%
0.0058
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-770

Связанные уязвимости

ubuntu
почти 11 лет назад

OpenStack Image Registry and Delivery Service (Glance) 2014.2 through 2014.2.2 does not properly remove images, which allows remote authenticated users to cause a denial of service (disk consumption) by creating a large number of images using the task v2 API and then deleting them, a different vulnerability than CVE-2014-9684.

redhat
почти 11 лет назад

OpenStack Image Registry and Delivery Service (Glance) 2014.2 through 2014.2.2 does not properly remove images, which allows remote authenticated users to cause a denial of service (disk consumption) by creating a large number of images using the task v2 API and then deleting them, a different vulnerability than CVE-2014-9684.

nvd
почти 11 лет назад

OpenStack Image Registry and Delivery Service (Glance) 2014.2 through 2014.2.2 does not properly remove images, which allows remote authenticated users to cause a denial of service (disk consumption) by creating a large number of images using the task v2 API and then deleting them, a different vulnerability than CVE-2014-9684.

debian
почти 11 лет назад

OpenStack Image Registry and Delivery Service (Glance) 2014.2 through ...

EPSS

Процентиль: 68%
0.0058
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-770