CVE-2014-5356
published 2014-08-25CVE-2014-5356: OpenStack Image Registry and Delivery Service (Glance) before 2013.2.4, 2014.x before 2014.1.3, and Juno before Juno-3, when using the V2 API, does not…
PriorityP418medium4CVSS 2.0
AVNACLAuSCNINAP
EPSS
2.13%
79.8th percentile
OpenStack Image Registry and Delivery Service (Glance) before 2013.2.4, 2014.x before 2014.1.3, and Juno before Juno-3, when using the V2 API, does not properly enforce the image_size_cap configuration option, which allows remote authenticated users to cause a denial of service (disk consumption) by uploading a large image.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| debian | glance | < glance 2014.1.3-1 (bookworm) | glance 2014.1.3-1 (bookworm) |
| glance_project | glance | >= 0 < 2014.1.3-1 | 2014.1.3-1 |
| glance_project | glance | >= 0 < 2014.1.3-1 | 2014.1.3-1 |
| glance_project | glance | >= 0 < 2014.1.3-1 | 2014.1.3-1 |
| glance_project | glance | >= 0 < 2014.1.3-1 | 2014.1.3-1 |
| glance_project | glance | >= 0 < 11.0.0a0 | 11.0.0a0 |
| openstack | image_registry_and_delivery_service | <= 2013.2.3 | — |
| openstack | image_registry_and_delivery_service | — | — |
| openstack | image_registry_and_delivery_service | — | — |
| openstack | image_registry_and_delivery_service | — | — |
| openstack | image_registry_and_delivery_service | — | — |
| openstack | image_registry_and_delivery_service | — | — |
| openstack | image_registry_and_delivery_service | — | — |
| openstack | image_registry_and_delivery_service | — | — |
| openstack | image_registry_and_delivery_service | — | — |
CVSS provenance
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
osv4.0MEDIUM
vendor_debian4.0MEDIUM
vendor_redhat4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
OpenStack Glance improper validation of the image_size_cap configuration option
ghsa·2022-05-17
CVE-2014-5356 [MEDIUM] OpenStack Glance improper validation of the image_size_cap configuration option
OpenStack Glance improper validation of the image_size_cap configuration option
OpenStack Image Registry and Delivery Service (Glance) before 2013.2.4, 2014.x before 2014.1.3, and Juno before Juno-3, when using the V2 API, does not properly enforce the image_size_cap configuration option, which allows remote authenticated users to cause a denial of service (disk consumption) by uploading a large image.
OSV
OpenStack Glance improper validation of the image_size_cap configuration option
osv·2022-05-17
CVE-2014-5356 [MEDIUM] OpenStack Glance improper validation of the image_size_cap configuration option
OpenStack Glance improper validation of the image_size_cap configuration option
OpenStack Image Registry and Delivery Service (Glance) before 2013.2.4, 2014.x before 2014.1.3, and Juno before Juno-3, when using the V2 API, does not properly enforce the image_size_cap configuration option, which allows remote authenticated users to cause a denial of service (disk consumption) by uploading a large image.
OSV
CVE-2014-5356: OpenStack Image Registry and Delivery Service (Glance) before 2013
osv·2014-08-25·CVSS 4.0
CVE-2014-5356 [MEDIUM] CVE-2014-5356: OpenStack Image Registry and Delivery Service (Glance) before 2013
OpenStack Image Registry and Delivery Service (Glance) before 2013.2.4, 2014.x before 2014.1.3, and Juno before Juno-3, when using the V2 API, does not properly enforce the image_size_cap configuration option, which allows remote authenticated users to cause a denial of service (disk consumption) by uploading a large image.
Ubuntu
OpenStack Glance vulnerability
vendor_ubuntu·2014-08-21
CVE-2014-5356 OpenStack Glance vulnerability
Title: OpenStack Glance vulnerability
Summary: OpenStack Glance could be made to stop serving requests.
Thomas Leaman and Stuart McLaren discovered that OpenStack Glance did not
properly honor the image_size_cap configuration option. A remote
authenticated attacker could exploit this to cause a denial of service via
disk consumption.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
openstack-glance: Glance store disk space exhaustion
vendor_redhat·2014-05-02·CVSS 4.0
CVE-2014-5356 [MEDIUM] CWE-20 openstack-glance: Glance store disk space exhaustion
openstack-glance: Glance store disk space exhaustion
OpenStack Image Registry and Delivery Service (Glance) before 2013.2.4, 2014.x before 2014.1.3, and Juno before Juno-3, when using the V2 API, does not properly enforce the image_size_cap configuration option, which allows remote authenticated users to cause a denial of service (disk consumption) by uploading a large image.
It was discovered that the image_size_cap configuration option in glance was not honored. An authenticated user could use this flaw to upload an image to glance and consume all available storage space, resulting in a denial of service.
Debian
CVE-2014-5356: glance - OpenStack Image Registry and Delivery Service (Glance) before 2013.2.4, 2014.x b...
vendor_debian·2014·CVSS 4.0
CVE-2014-5356 [MEDIUM] CVE-2014-5356: glance - OpenStack Image Registry and Delivery Service (Glance) before 2013.2.4, 2014.x b...
OpenStack Image Registry and Delivery Service (Glance) before 2013.2.4, 2014.x before 2014.1.3, and Juno before Juno-3, when using the V2 API, does not properly enforce the image_size_cap configuration option, which allows remote authenticated users to cause a denial of service (disk consumption) by uploading a large image.
Scope: local
bookworm: resolved (fixed in 2014.1.3-1)
bullseye: resolved (fixed in 2014.1.3-1)
forky: resolved (fixed in 2014.1.3-1)
sid: resolved (fixed in 2014.1.3-1)
trixie: resolved (fixed in 2014.1.3-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-5356 openstack-glance: Glance store disk space exhaustion [epel-6]
bugzilla·2014-08-20·CVSS 4.0
CVE-2014-5356 [MEDIUM] CVE-2014-5356 openstack-glance: Glance store disk space exhaustion [epel-6]
CVE-2014-5356 openstack-glance: Glance store disk space exhaustion [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
epel-6 tracking bug for openstack-glance: see blocks
Bugzilla
CVE-2014-5356 openstack-glance: Glance store disk space exhaustion
bugzilla·2014-08-20·CVSS 4.0
CVE-2014-5356 [MEDIUM] CVE-2014-5356 openstack-glance: Glance store disk space exhaustion
CVE-2014-5356 openstack-glance: Glance store disk space exhaustion
The OpenStack project reports:
""
Thomas Leaman and Stuart McLaren from Hewlett Packard reported a
vulnerability in Glance. By uploading a large enough image to a Glance
store, an authenticated user may fill the store space because the
image_size_cap configuration option is not honored. This may prevent
further image upload and/or cause service disruption. Note that the
import method is not affected. All Glance setups using API v2 are
affected (unless you use a policy to restrict/disable image upload).
""
This affects versions up to 2013.2.3 and 2014.1 to 2014.1.2.
References:
http://seclists.org/oss-sec/2014/q3/410
https://bugs.launchpad.net/glance/+bug/1315321
https://review.openstack.org/#/c/91764/
Discussion:
Cre
Bugzilla
CVE-2014-5356 openstack-glance: Glance store disk space exhaustion [fedora-20]
bugzilla·2014-08-20·CVSS 4.0
CVE-2014-5356 [MEDIUM] CVE-2014-5356 openstack-glance: Glance store disk space exhaustion [fedora-20]
CVE-2014-5356 openstack-glance: Glance store disk space exhaustion [fedora-20]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
fedora-20 tracking bug for openstack-glance: see blocks
Bugzilla
CVE-2014-5356 openstack-glance: Glance store disk space exhaustion [fedora-19]
bugzilla·2014-08-20·CVSS 4.0
CVE-2014-5356 [MEDIUM] CVE-2014-5356 openstack-glance: Glance store disk space exhaustion [fedora-19]
CVE-2014-5356 openstack-glance: Glance store disk space exhaustion [fedora-19]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
fedora-19 tracking bug for openstack-glance: see blocks
http://rhn.redhat.com/errata/RHSA-2014-1337.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1338.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1685.htmlhttp://secunia.com/advisories/60743http://www.openwall.com/lists/oss-security/2014/08/21/6http://www.ubuntu.com/usn/USN-2322-1https://bugs.launchpad.net/glance/+bug/1315321http://rhn.redhat.com/errata/RHSA-2014-1337.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1338.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1685.htmlhttp://secunia.com/advisories/60743http://www.openwall.com/lists/oss-security/2014/08/21/6http://www.ubuntu.com/usn/USN-2322-1https://bugs.launchpad.net/glance/+bug/1315321
2014-08-25
Published