CVE-2014-9684
published 2015-02-24CVE-2014-9684: OpenStack Image Registry and Delivery Service (Glance) 2014.2 through 2014.2.2 does not properly remove images, which allows remote authenticated users to…
PriorityP418medium4CVSS 2.0
AVNACLAuSCNINAP
EPSS
2.00%
79.2th percentile
OpenStack Image Registry and Delivery Service (Glance) 2014.2 through 2014.2.2 does not properly remove images, which allows remote authenticated users to cause a denial of service (disk consumption) by creating a large number of images using the task v2 API and then deleting them before the uploads finish, a different vulnerability than CVE-2015-1881.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | glance | — | — |
| glance_project | glance | >= 0 < 11.0.0a0 | 11.0.0a0 |
| openstack | image_registry_and_delivery_service | — | — |
| openstack | image_registry_and_delivery_service | — | — |
| openstack | image_registry_and_delivery_service | — | — |
CVSS provenance
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
ghsa4.0MEDIUM
osv4.0MEDIUM
vendor_debian4.0LOW
vendor_redhat4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
OpenStack Glance Denial of service by creating a large number of images
osv·2022-05-17·CVSS 4.0
CVE-2014-9684 [MEDIUM] OpenStack Glance Denial of service by creating a large number of images
OpenStack Glance Denial of service by creating a large number of images
OpenStack Image Registry and Delivery Service (Glance) 2014.2 through 2014.2.2 does not properly remove images, which allows remote authenticated users to cause a denial of service (disk consumption) by creating a large number of images using the task v2 API and then deleting them before the uploads finish, a different vulnerability than CVE-2015-1881.
OSV
OpenStack Glance Denial of service by creating a large number of images
osv·2022-05-17·CVSS 4.0
CVE-2015-1881 [MEDIUM] OpenStack Glance Denial of service by creating a large number of images
OpenStack Glance Denial of service by creating a large number of images
OpenStack Image Registry and Delivery Service (Glance) 2014.2 through 2014.2.2 does not properly remove images, which allows remote authenticated users to cause a denial of service (disk consumption) by creating a large number of images using the task v2 API and then deleting them, a different vulnerability than CVE-2014-9684.
GHSA
OpenStack Glance Denial of service by creating a large number of images
ghsa·2022-05-17·CVSS 4.0
CVE-2014-9684 [MEDIUM] CWE-770 OpenStack Glance Denial of service by creating a large number of images
OpenStack Glance Denial of service by creating a large number of images
OpenStack Image Registry and Delivery Service (Glance) 2014.2 through 2014.2.2 does not properly remove images, which allows remote authenticated users to cause a denial of service (disk consumption) by creating a large number of images using the task v2 API and then deleting them before the uploads finish, a different vulnerability than CVE-2015-1881.
GHSA
OpenStack Glance Denial of service by creating a large number of images
ghsa·2022-05-17·CVSS 4.0
CVE-2015-1881 [MEDIUM] CWE-770 OpenStack Glance Denial of service by creating a large number of images
OpenStack Glance Denial of service by creating a large number of images
OpenStack Image Registry and Delivery Service (Glance) 2014.2 through 2014.2.2 does not properly remove images, which allows remote authenticated users to cause a denial of service (disk consumption) by creating a large number of images using the task v2 API and then deleting them, a different vulnerability than CVE-2014-9684.
OSV
CVE-2014-9684: OpenStack Image Registry and Delivery Service (Glance) 2014
osv·2015-02-24·CVSS 4.0
CVE-2014-9684 [MEDIUM] CVE-2014-9684: OpenStack Image Registry and Delivery Service (Glance) 2014
OpenStack Image Registry and Delivery Service (Glance) 2014.2 through 2014.2.2 does not properly remove images, which allows remote authenticated users to cause a denial of service (disk consumption) by creating a large number of images using the task v2 API and then deleting them before the uploads finish, a different vulnerability than CVE-2015-1881.
OSV
CVE-2015-1881: OpenStack Image Registry and Delivery Service (Glance) 2014
osv·2015-02-24·CVSS 4.0
CVE-2015-1881 [MEDIUM] CVE-2015-1881: OpenStack Image Registry and Delivery Service (Glance) 2014
OpenStack Image Registry and Delivery Service (Glance) 2014.2 through 2014.2.2 does not properly remove images, which allows remote authenticated users to cause a denial of service (disk consumption) by creating a large number of images using the task v2 API and then deleting them, a different vulnerability than CVE-2014-9684.
Red Hat
openstack-glance: potential resource exhaustion and denial of service using images manipulation API
vendor_redhat·2015-02-19·CVSS 4.0
CVE-2014-9684 [MEDIUM] CWE-400 openstack-glance: potential resource exhaustion and denial of service using images manipulation API
openstack-glance: potential resource exhaustion and denial of service using images manipulation API
OpenStack Image Registry and Delivery Service (Glance) 2014.2 through 2014.2.2 does not properly remove images, which allows remote authenticated users to cause a denial of service (disk consumption) by creating a large number of images using the task v2 API and then deleting them before the uploads finish, a different vulnerability than CVE-2015-1881.
Multiple flaws were found in the glance task API that could cause untracked image data to be left in the back end. A malicious user could use these flaws to deliberately accumulate untracked image data, and cause a denial of service via resource exhaustion.
Package: openstack-glance (Red Hat Enterprise Linux OpenStack Platform 5 (Icehouse))
Red Hat
openstack-glance: potential resource exhaustion and denial of service using images manipulation API
vendor_redhat·2015-02-19·CVSS 4.0
CVE-2015-1881 [MEDIUM] CWE-400 openstack-glance: potential resource exhaustion and denial of service using images manipulation API
openstack-glance: potential resource exhaustion and denial of service using images manipulation API
OpenStack Image Registry and Delivery Service (Glance) 2014.2 through 2014.2.2 does not properly remove images, which allows remote authenticated users to cause a denial of service (disk consumption) by creating a large number of images using the task v2 API and then deleting them, a different vulnerability than CVE-2014-9684.
Multiple flaws were found in the glance task API that could cause untracked image data to be left in the back end. A malicious user could use these flaws to deliberately accumulate untracked image data, and cause a denial of service via resource exhaustion.
Package: openstack-glance (Red Hat Enterprise Linux OpenStack Platform 5 (Icehouse)) - Not affected
Package:
Debian
CVE-2015-1881: glance - OpenStack Image Registry and Delivery Service (Glance) 2014.2 through 2014.2.2 d...
vendor_debian·2015·CVSS 4.0
CVE-2015-1881 [MEDIUM] CVE-2015-1881: glance - OpenStack Image Registry and Delivery Service (Glance) 2014.2 through 2014.2.2 d...
OpenStack Image Registry and Delivery Service (Glance) 2014.2 through 2014.2.2 does not properly remove images, which allows remote authenticated users to cause a denial of service (disk consumption) by creating a large number of images using the task v2 API and then deleting them, a different vulnerability than CVE-2014-9684.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
Debian
CVE-2014-9684: glance - OpenStack Image Registry and Delivery Service (Glance) 2014.2 through 2014.2.2 d...
vendor_debian·2014·CVSS 4.0
CVE-2014-9684 [MEDIUM] CVE-2014-9684: glance - OpenStack Image Registry and Delivery Service (Glance) 2014.2 through 2014.2.2 d...
OpenStack Image Registry and Delivery Service (Glance) 2014.2 through 2014.2.2 does not properly remove images, which allows remote authenticated users to cause a denial of service (disk consumption) by creating a large number of images using the task v2 API and then deleting them before the uploads finish, a different vulnerability than CVE-2015-1881.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
No detection rules found.
No public exploits indexed.
http://lists.openstack.org/pipermail/openstack-announce/2015-February/000336.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0938.htmlhttp://www.securityfocus.com/bid/72692https://bugs.launchpad.net/glance/+bug/1371118http://lists.openstack.org/pipermail/openstack-announce/2015-February/000336.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0938.htmlhttp://www.securityfocus.com/bid/72692https://bugs.launchpad.net/glance/+bug/1371118
2015-02-24
Published