Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-9623

Опубликовано: 16 янв. 2015
Источник: redhat
CVSS2: 2.1

Описание

OpenStack Glance 2014.2.x through 2014.2.1, 2014.1.3, and earlier allows remote authenticated users to bypass the storage quota and cause a denial of service (disk consumption) by deleting an image in the saving state.

A storage quota bypass flaw was found in OpenStack Image (glance). If an image was deleted while it was being uploaded, it would not count towards a user's quota. A malicious user could use this flaw to deliberately fill the backing store, and cause a denial of service.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenStack Platform 4openstack-glanceWill not fix
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6openstack-glanceFixedRHSA-2015:083816.04.2015
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7openstack-glanceFixedRHSA-2015:083716.04.2015
Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7openstack-glanceFixedRHSA-2015:064405.03.2015
Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7python-glanceclientFixedRHSA-2015:064405.03.2015

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-841->CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=1183647openstack-glance: user storage quota bypass

2.1 Low

CVSS2

Связанные уязвимости

ubuntu
около 11 лет назад

OpenStack Glance 2014.2.x through 2014.2.1, 2014.1.3, and earlier allows remote authenticated users to bypass the storage quota and cause a denial of service (disk consumption) by deleting an image in the saving state.

nvd
около 11 лет назад

OpenStack Glance 2014.2.x through 2014.2.1, 2014.1.3, and earlier allows remote authenticated users to bypass the storage quota and cause a denial of service (disk consumption) by deleting an image in the saving state.

debian
около 11 лет назад

OpenStack Glance 2014.2.x through 2014.2.1, 2014.1.3, and earlier allo ...

github
больше 3 лет назад

OpenStack Glance Bypass the storage quota and Denial of service

2.1 Low

CVSS2