cbcvebase.
CVE-2015-5286
published 2015-10-26

CVE-2015-5286: OpenStack Image Service (Glance) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) allows remote authenticated users to bypass the storage quota and…

PriorityP426medium6.8CVSS 2.0
AVNACLAuSCNINAC
EPSS
2.38%
81.9th percentile
OpenStack Image Service (Glance) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) allows remote authenticated users to bypass the storage quota and cause a denial of service (disk consumption) by deleting images that are being uploaded using a token that expires during the process. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-9623.

Affected

11 ranges
VendorProductVersion rangeFixed in
debianglance< glance 1:11.0.0-1 (bookworm)glance 1:11.0.0-1 (bookworm)
glance_projectglance>= 0 < 1:11.0.0-11:11.0.0-1
glance_projectglance>= 0 < 1:11.0.0-11:11.0.0-1
glance_projectglance>= 0 < 1:11.0.0-11:11.0.0-1
glance_projectglance>= 0 < 1:11.0.0-11:11.0.0-1
glance_projectglance>= 0 < 2014.2.42014.2.4
glance_projectglance>= 0 < 1:2014.1.5-0ubuntu1.11:2014.1.5-0ubuntu1.1
glance_projectglance>= 2015.1.0 < 2015.1.22015.1.2
openstackimage_registry_and_delivery_service<= 2014.2.3
openstackimage_registry_and_delivery_service
openstackimage_registry_and_delivery_service

CVSS provenance

nvdv2.06.8MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:C
ghsa4.0MEDIUM
osv5.5MEDIUM
vendor_ubuntu5.5MEDIUM
vendor_debian4.0MEDIUM
vendor_redhat4.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.