Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-5356

Опубликовано: 02 мая 2014
Источник: redhat
CVSS2: 4
EPSS Низкий

Описание

OpenStack Image Registry and Delivery Service (Glance) before 2013.2.4, 2014.x before 2014.1.3, and Juno before Juno-3, when using the V2 API, does not properly enforce the image_size_cap configuration option, which allows remote authenticated users to cause a denial of service (disk consumption) by uploading a large image.

It was discovered that the image_size_cap configuration option in glance was not honored. An authenticated user could use this flaw to upload an image to glance and consume all available storage space, resulting in a denial of service.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-20->CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=1131770openstack-glance: Glance store disk space exhaustion

EPSS

Процентиль: 74%
0.00804
Низкий

4 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 11 лет назад

OpenStack Image Registry and Delivery Service (Glance) before 2013.2.4, 2014.x before 2014.1.3, and Juno before Juno-3, when using the V2 API, does not properly enforce the image_size_cap configuration option, which allows remote authenticated users to cause a denial of service (disk consumption) by uploading a large image.

nvd
больше 11 лет назад

OpenStack Image Registry and Delivery Service (Glance) before 2013.2.4, 2014.x before 2014.1.3, and Juno before Juno-3, when using the V2 API, does not properly enforce the image_size_cap configuration option, which allows remote authenticated users to cause a denial of service (disk consumption) by uploading a large image.

debian
больше 11 лет назад

OpenStack Image Registry and Delivery Service (Glance) before 2013.2.4 ...

github
больше 3 лет назад

OpenStack Glance improper validation of the image_size_cap configuration option

EPSS

Процентиль: 74%
0.00804
Низкий

4 Medium

CVSS2