CVE-2015-1881

OpenStack Glance 2014.2-2014.2.2 Authenticated DoS via Task v2 API Image Deletion

Title source: llm
STIX 2.1

Description

OpenStack Image Registry and Delivery Service (Glance) 2014.2 through 2014.2.2 does not properly remove images, which allows remote authenticated users to cause a denial of service (disk consumption) by creating a large number of images using the task v2 API and then deleting them, a different vulnerability than CVE-2014-9684.

References (4)

Core 4
Core References
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2015-0938.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/72694

Scores

EPSS 0.0058
EPSS Percentile 69.1%

Details

CWE
CWE-399
Status published
Products (4)
openstack/image_registry_and_delivery_service_\(glance\) 2014.2
openstack/image_registry_and_delivery_service_\(glance\) 2014.2.1
openstack/image_registry_and_delivery_service_\(glance\) 2014.2.2
pypi/glance 0 - 11.0.0a0PyPI
Published Feb 24, 2015
Tracked Since Feb 18, 2026