CVE-2014-9623
published 2015-01-23CVE-2014-9623: OpenStack Glance 2014.2.x through 2014.2.1, 2014.1.3, and earlier allows remote authenticated users to bypass the storage quota and cause a denial of service…
PriorityP417medium4CVSS 2.0
AVNACLAuSCNINAP
EPSS
2.84%
85.0th percentile
OpenStack Glance 2014.2.x through 2014.2.1, 2014.1.3, and earlier allows remote authenticated users to bypass the storage quota and cause a denial of service (disk consumption) by deleting an image in the saving state.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | glance | < glance 2014.1.3-12 (bookworm) | glance 2014.1.3-12 (bookworm) |
| debian | glance | < glance 1:11.0.0-1 (bookworm) | glance 1:11.0.0-1 (bookworm) |
| glance_project | glance | >= 0 < 2014.1.3-12 | 2014.1.3-12 |
| glance_project | glance | >= 0 < 1:11.0.0-1 | 1:11.0.0-1 |
| glance_project | glance | >= 0 < 2014.1.3-12 | 2014.1.3-12 |
| glance_project | glance | >= 0 < 1:11.0.0-1 | 1:11.0.0-1 |
| glance_project | glance | >= 0 < 2014.1.3-12 | 2014.1.3-12 |
| glance_project | glance | >= 0 < 1:11.0.0-1 | 1:11.0.0-1 |
| glance_project | glance | >= 0 < 2014.1.3-12 | 2014.1.3-12 |
| glance_project | glance | >= 0 < 1:11.0.0-1 | 1:11.0.0-1 |
| glance_project | glance | >= 0 < 11.0.0a0 | 11.0.0a0 |
| glance_project | glance | >= 0 < 2014.2.4 | 2014.2.4 |
| glance_project | glance | >= 2015.1.0 < 2015.1.2 | 2015.1.2 |
| openstack | image_registry_and_delivery_service | <= 2014.1.3 | — |
| openstack | image_registry_and_delivery_service | <= 2014.2.3 | — |
| openstack | image_registry_and_delivery_service | — | — |
| openstack | image_registry_and_delivery_service | — | — |
| openstack | image_registry_and_delivery_service | — | — |
| redhat | openstack | — | — |
CVSS provenance
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
ghsa4.0MEDIUM
osv4.0MEDIUM
vendor_debian4.0MEDIUM
vendor_redhat4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
OpenStack Glance Bypass the storage quota and Denial of service
osv·2022-05-17
CVE-2014-9623 [MEDIUM] OpenStack Glance Bypass the storage quota and Denial of service
OpenStack Glance Bypass the storage quota and Denial of service
OpenStack Glance 2014.2.x through 2014.2.1, 2014.1.3, and earlier allows remote authenticated users to bypass the storage quota and cause a denial of service (disk consumption) by deleting an image in the saving state.
GHSA
OpenStack Image Service (Glance) allows remote authenticated users to bypass storage quota, cause denial of service
ghsa·2022-05-17·CVSS 4.0
CVE-2015-5286 [MEDIUM] CWE-400 OpenStack Image Service (Glance) allows remote authenticated users to bypass storage quota, cause denial of service
OpenStack Image Service (Glance) allows remote authenticated users to bypass storage quota, cause denial of service
OpenStack Image Service (Glance) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) allows remote authenticated users to bypass the storage quota and cause a denial of service (disk consumption) by deleting images that are being uploaded using a token that expires during the process. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-9623.
OSV
OpenStack Image Service (Glance) allows remote authenticated users to bypass storage quota, cause denial of service
osv·2022-05-17·CVSS 4.0
CVE-2015-5286 [MEDIUM] OpenStack Image Service (Glance) allows remote authenticated users to bypass storage quota, cause denial of service
OpenStack Image Service (Glance) allows remote authenticated users to bypass storage quota, cause denial of service
OpenStack Image Service (Glance) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) allows remote authenticated users to bypass the storage quota and cause a denial of service (disk consumption) by deleting images that are being uploaded using a token that expires during the process. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-9623.
GHSA
OpenStack Glance Bypass the storage quota and Denial of service
ghsa·2022-05-17
CVE-2014-9623 [MEDIUM] OpenStack Glance Bypass the storage quota and Denial of service
OpenStack Glance Bypass the storage quota and Denial of service
OpenStack Glance 2014.2.x through 2014.2.1, 2014.1.3, and earlier allows remote authenticated users to bypass the storage quota and cause a denial of service (disk consumption) by deleting an image in the saving state.
OSV
CVE-2015-5286: OpenStack Image Service (Glance) before 2014
osv·2015-10-26·CVSS 4.0
CVE-2015-5286 [MEDIUM] CVE-2015-5286: OpenStack Image Service (Glance) before 2014
OpenStack Image Service (Glance) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) allows remote authenticated users to bypass the storage quota and cause a denial of service (disk consumption) by deleting images that are being uploaded using a token that expires during the process. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-9623.
OSV
CVE-2014-9623: OpenStack Glance 2014
osv·2015-01-23·CVSS 4.0
CVE-2014-9623 [MEDIUM] CVE-2014-9623: OpenStack Glance 2014
OpenStack Glance 2014.2.x through 2014.2.1, 2014.1.3, and earlier allows remote authenticated users to bypass the storage quota and cause a denial of service (disk consumption) by deleting an image in the saving state.
Red Hat
openstack-glance: Storage overrun by deleting images
vendor_redhat·2015-10-01·CVSS 4.0
CVE-2015-5286 [MEDIUM] CWE-400 openstack-glance: Storage overrun by deleting images
openstack-glance: Storage overrun by deleting images
OpenStack Image Service (Glance) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) allows remote authenticated users to bypass the storage quota and cause a denial of service (disk consumption) by deleting images that are being uploaded using a token that expires during the process. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-9623.
A race-condition flaw was discovered in the OpenStack Image service (glance). When images in the upload state were deleted using a token close to expiration, untracked image data could accumulate in the back end. Because untracked data does not count towards the storage quota, an attacker could use this flaw to cause a denial of service through resource exhaustion.
Red Hat
openstack-glance: user storage quota bypass
vendor_redhat·2015-01-16·CVSS 4.0
CVE-2014-9623 [MEDIUM] CWE-841 openstack-glance: user storage quota bypass
openstack-glance: user storage quota bypass
OpenStack Glance 2014.2.x through 2014.2.1, 2014.1.3, and earlier allows remote authenticated users to bypass the storage quota and cause a denial of service (disk consumption) by deleting an image in the saving state.
A storage quota bypass flaw was found in OpenStack Image (glance). If an image was deleted while it was being uploaded, it would not count towards a user's quota. A malicious user could use this flaw to deliberately fill the backing store, and cause a denial of service.
Package: openstack-glance (Red Hat OpenStack Platform 4) - Will not fix
Debian
CVE-2015-5286: glance - OpenStack Image Service (Glance) before 2014.2.4 (juno) and 2015.1.x before 2015...
vendor_debian·2015·CVSS 4.0
CVE-2015-5286 [MEDIUM] CVE-2015-5286: glance - OpenStack Image Service (Glance) before 2014.2.4 (juno) and 2015.1.x before 2015...
OpenStack Image Service (Glance) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) allows remote authenticated users to bypass the storage quota and cause a denial of service (disk consumption) by deleting images that are being uploaded using a token that expires during the process. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-9623.
Scope: local
bookworm: resolved (fixed in 1:11.0.0-1)
bullseye: resolved (fixed in 1:11.0.0-1)
forky: resolved (fixed in 1:11.0.0-1)
sid: resolved (fixed in 1:11.0.0-1)
trixie: resolved (fixed in 1:11.0.0-1)
Debian
CVE-2014-9623: glance - OpenStack Glance 2014.2.x through 2014.2.1, 2014.1.3, and earlier allows remote ...
vendor_debian·2014·CVSS 4.0
CVE-2014-9623 [MEDIUM] CVE-2014-9623: glance - OpenStack Glance 2014.2.x through 2014.2.1, 2014.1.3, and earlier allows remote ...
OpenStack Glance 2014.2.x through 2014.2.1, 2014.1.3, and earlier allows remote authenticated users to bypass the storage quota and cause a denial of service (disk consumption) by deleting an image in the saving state.
Scope: local
bookworm: resolved (fixed in 2014.1.3-12)
bullseye: resolved (fixed in 2014.1.3-12)
forky: resolved (fixed in 2014.1.3-12)
sid: resolved (fixed in 2014.1.3-12)
trixie: resolved (fixed in 2014.1.3-12)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-9623 openstack-glance: user storage quota bypass [fedora-all]
bugzilla·2015-01-29·CVSS 4.0
CVE-2014-9623 [MEDIUM] CVE-2014-9623 openstack-glance: user storage quota bypass [fedora-all]
CVE-2014-9623 openstack-glance: user storage quota bypass [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora.
Bugzilla
CVE-2014-9623 openstack-glance: user storage quota bypass
bugzilla·2015-01-19·CVSS 4.0
CVE-2014-9623 [MEDIUM] CVE-2014-9623 openstack-glance: user storage quota bypass
CVE-2014-9623 openstack-glance: user storage quota bypass
Title: Glance user storage quota bypass
Reporter: Tushar Patil (NTT)
Products: Glance
Versions: up to 2014.1.3 and 2014.2 version up to 2014.2.1
Description:
Tushar Patil from NTT reported a vulnerability in Glance. By deleting images
that are being uploaded, a malicious user can overcome the storage quota and
thus may overrun the backend. Images in deleted state are not taken into
account by quota and won't be effectively deleted until the upload is
completed. Only Glance setups configured with user_storage_quota are
affected.
References:
https://launchpad.net/bugs/1398830
Acknowledgements:
Red Hat would like to thank the OpenStack project for reporting this issue. Upstream acknowledges Tushar Patil of NTT as the original repo
http://rhn.redhat.com/errata/RHSA-2015-0644.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0837.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0838.htmlhttp://secunia.com/advisories/62165http://www.openwall.com/lists/oss-security/2015/01/18/4http://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.htmlhttps://bugs.launchpad.net/glance/+bug/1383973https://bugs.launchpad.net/glance/+bug/1398830https://security.openstack.org/ossa/OSSA-2015-003.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0644.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0837.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0838.htmlhttp://secunia.com/advisories/62165http://www.openwall.com/lists/oss-security/2015/01/18/4http://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.htmlhttps://bugs.launchpad.net/glance/+bug/1383973https://bugs.launchpad.net/glance/+bug/1398830https://security.openstack.org/ossa/OSSA-2015-003.html
2015-01-23
Published