CVE-2015-3289

Severity
4.0MEDIUM
EPSS
0.4%
top 41.65%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 14
Latest updateMay 17

Description

OpenStack Glance before 2015.1.1 (kilo) allows remote authenticated users to cause a denial of service (disk consumption) by repeatedly using the import task flow API to create images and then deleting them.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 8.0 | Impact: 2.9

Affected Packages2 packages

NVDopenstack/glance2015.1.0
Debianglance< 2015.1.0-4+3

Patches

🔴Vulnerability Details

3
GHSA
GHSA-6c9r-5vjm-r3gh: OpenStack Glance before 20152022-05-17
OSV
CVE-2015-3289: OpenStack Glance before 20152015-08-14
CVEList
CVE-2015-3289: OpenStack Glance before 20152015-08-14

📋Vendor Advisories

2
Red Hat
openstack-glance: potential resource exhaustion task flow API2015-07-28
Debian
CVE-2015-3289: glance - OpenStack Glance before 2015.1.1 (kilo) allows remote authenticated users to cau...2015

💬Community

1
Bugzilla
CVE-2015-3289 openstack-glance: potential resource exhaustion task flow API2015-07-16
CVE-2015-3289 (MEDIUM CVSS 4) | OpenStack Glance before 2015.1.1 (k | cvebase.io