// For flags

CVE-2014-5356

openstack-glance: Glance store disk space exhaustion

Severity Score

4.0
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

OpenStack Image Registry and Delivery Service (Glance) before 2013.2.4, 2014.x before 2014.1.3, and Juno before Juno-3, when using the V2 API, does not properly enforce the image_size_cap configuration option, which allows remote authenticated users to cause a denial of service (disk consumption) by uploading a large image.

OpenStack Image Registry and Delivery Service (Glance) anterior a 2013.2.4, 2014.x anterior a 2014.1.3, y Juno anterior a Juno-3, cuando utiliza la API V2, no aplica debidamente la opción de configuración image_size_cap, lo que permite a usuarios remotos autenticados causar una denegación de servicio (el consumo del disco) mediante la subida de un imagen grande.

It was discovered that the image_size_cap configuration option in glance was not honored. An authenticated user could use this flaw to upload an image to glance and consume all available storage space, resulting in a denial of service.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
Single
Confidentiality
None
Integrity
None
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2014-08-19 CVE Reserved
  • 2014-08-21 CVE Published
  • 2024-04-06 EPSS Updated
  • 2024-08-06 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-264: Permissions, Privileges, and Access Controls
  • CWE-400: Uncontrolled Resource Consumption
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Openstack
Search vendor "Openstack"
Image Registry And Delivery Service \(glance\)
Search vendor "Openstack" for product "Image Registry And Delivery Service \(glance\)"
<= 2013.2.3
Search vendor "Openstack" for product "Image Registry And Delivery Service \(glance\)" and version " <= 2013.2.3"
-
Affected
Openstack
Search vendor "Openstack"
Image Registry And Delivery Service \(glance\)
Search vendor "Openstack" for product "Image Registry And Delivery Service \(glance\)"
2013.2
Search vendor "Openstack" for product "Image Registry And Delivery Service \(glance\)" and version "2013.2"
-
Affected
Openstack
Search vendor "Openstack"
Image Registry And Delivery Service \(glance\)
Search vendor "Openstack" for product "Image Registry And Delivery Service \(glance\)"
2013.2.1
Search vendor "Openstack" for product "Image Registry And Delivery Service \(glance\)" and version "2013.2.1"
-
Affected
Openstack
Search vendor "Openstack"
Image Registry And Delivery Service \(glance\)
Search vendor "Openstack" for product "Image Registry And Delivery Service \(glance\)"
2013.2.2
Search vendor "Openstack" for product "Image Registry And Delivery Service \(glance\)" and version "2013.2.2"
-
Affected
Openstack
Search vendor "Openstack"
Image Registry And Delivery Service \(glance\)
Search vendor "Openstack" for product "Image Registry And Delivery Service \(glance\)"
2014.1
Search vendor "Openstack" for product "Image Registry And Delivery Service \(glance\)" and version "2014.1"
-
Affected
Openstack
Search vendor "Openstack"
Image Registry And Delivery Service \(glance\)
Search vendor "Openstack" for product "Image Registry And Delivery Service \(glance\)"
2014.1.1
Search vendor "Openstack" for product "Image Registry And Delivery Service \(glance\)" and version "2014.1.1"
-
Affected
Openstack
Search vendor "Openstack"
Image Registry And Delivery Service \(glance\)
Search vendor "Openstack" for product "Image Registry And Delivery Service \(glance\)"
2014.1.2
Search vendor "Openstack" for product "Image Registry And Delivery Service \(glance\)" and version "2014.1.2"
-
Affected
Openstack
Search vendor "Openstack"
Image Registry And Delivery Service \(glance\)
Search vendor "Openstack" for product "Image Registry And Delivery Service \(glance\)"
juno-1
Search vendor "Openstack" for product "Image Registry And Delivery Service \(glance\)" and version "juno-1"
-
Affected
Openstack
Search vendor "Openstack"
Image Registry And Delivery Service \(glance\)
Search vendor "Openstack" for product "Image Registry And Delivery Service \(glance\)"
juno-2
Search vendor "Openstack" for product "Image Registry And Delivery Service \(glance\)" and version "juno-2"
-
Affected
Canonical
Search vendor "Canonical"
Ubuntu Linux
Search vendor "Canonical" for product "Ubuntu Linux"
14.04
Search vendor "Canonical" for product "Ubuntu Linux" and version "14.04"
lts
Affected