cbcvebase.
CVE-2014-9623
published 2015-01-23

CVE-2014-9623: OpenStack Glance 2014.2.x through 2014.2.1, 2014.1.3, and earlier allows remote authenticated users to bypass the storage quota and cause a denial of service…

medium4CVSS 3.1
AVNACLAuSCNINAP
OpenStack Glance 2014.2.x through 2014.2.1, 2014.1.3, and earlier allows remote authenticated users to bypass the storage quota and cause a denial of service (disk consumption) by deleting an image in the saving state.

Affected

19 ranges
VendorProductVersion rangeFixed in
debianglance< glance 2014.1.3-12 (bookworm)glance 2014.1.3-12 (bookworm)
debianglance< glance 1:11.0.0-1 (bookworm)glance 1:11.0.0-1 (bookworm)
glance_projectglance>= 0 < 2014.1.3-122014.1.3-12
glance_projectglance>= 0 < 1:11.0.0-11:11.0.0-1
glance_projectglance>= 0 < 2014.1.3-122014.1.3-12
glance_projectglance>= 0 < 1:11.0.0-11:11.0.0-1
glance_projectglance>= 0 < 2014.1.3-122014.1.3-12
glance_projectglance>= 0 < 1:11.0.0-11:11.0.0-1
glance_projectglance>= 0 < 2014.1.3-122014.1.3-12
glance_projectglance>= 0 < 1:11.0.0-11:11.0.0-1
glance_projectglance>= 0 < 11.0.0a011.0.0a0
glance_projectglance>= 0 < 2014.2.42014.2.4
glance_projectglance>= 2015.1.0 < 2015.1.22015.1.2
openstackimage_registry_and_delivery_service<= 2014.1.3
openstackimage_registry_and_delivery_service<= 2014.2.3
openstackimage_registry_and_delivery_service
openstackimage_registry_and_delivery_service
openstackimage_registry_and_delivery_service
redhatopenstack

CVSS provenance

nvd6.8MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:C
ghsa4.0MEDIUM
osv4.0MEDIUM