4
CVSSv2

CVE-2015-3289

Published: 14/08/2015 Updated: 03/12/2016
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P

Vulnerability Summary

OpenStack Glance prior to 2015.1.1 (kilo) allows remote authenticated users to cause a denial of service (disk consumption) by repeatedly using the import task flow API to create images and then deleting them.

Vulnerable Product Search on Vulmon Subscribe to Product

openstack glance

Vendor Advisories

Debian Bug report logs - #793896 glance: CVE-2015-3289: Glance task flow may fail to delete image from backend Package: src:glance; Maintainer for src:glance is Debian OpenStack <team+openstack@trackerdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Tue, 28 Jul 2015 17:45:01 UTC Severity: imp ...
OpenStack Glance before 201511 (kilo) allows remote authenticated users to cause a denial of service (disk consumption) by repeatedly using the import task flow API to create images and then deleting them ...