Safety vulnerability ID: 35635
The information on this page was manually curated by our Cybersecurity Intelligence Team.
OpenStack Image Service (Glance) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) allows remote authenticated users to bypass the storage quota and cause a denial of service (disk consumption) by deleting images that are being uploaded using a token that expires during the process. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-9623.
Latest version: 29.0.0
OpenStack Image Service
OpenStack Image Service (Glance) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) allows remote authenticated users to bypass the storage quota and cause a denial of service (disk consumption) by deleting images that are being uploaded using a token that expires during the process. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-9623.
CONFIRM:https://bugs.launchpad.net/bugs/1498163: https://bugs.launchpad.net/bugs/1498163
CONFIRM:https://security.openstack.org/ossa/OSSA-2015-020.html: https://security.openstack.org/ossa/OSSA-2015-020.html
REDHAT:RHSA-2015:1897: http://rhn.redhat.com/errata/RHSA-2015-1897.html
BID:76943: http://www.securityfocus.com/bid/76943
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application