CVE-2014-5356
Published Aug 25, 2014
Last updated 8 years ago
Overview
- Description
- OpenStack Image Registry and Delivery Service (Glance) before 2013.2.4, 2014.x before 2014.1.3, and Juno before Juno-3, when using the V2 API, does not properly enforce the image_size_cap configuration option, which allows remote authenticated users to cause a denial of service (disk consumption) by uploading a large image.
- Source
- cve@mitre.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 4
- Impact score
- 2.9
- Exploitability score
- 8
- Vector string
- AV:N/AC:L/Au:S/C:N/I:N/A:P
Weaknesses
- nvd@nist.gov
- CWE-264
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:openstack:image_registry_and_delivery_service_\\(glance\\):*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FB2930CB-FAC9-4283-81A2-33CB02AE0463", "versionEndIncluding": "2013.2.3" }, { "criteria": "cpe:2.3:a:openstack:image_registry_and_delivery_service_\\(glance\\):2013.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5187A73A-0D13-442E-AC27-D995B652F184" }, { "criteria": "cpe:2.3:a:openstack:image_registry_and_delivery_service_\\(glance\\):2013.2.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "20E946F4-A78D-4444-8418-AB44F93FE603" }, { "criteria": "cpe:2.3:a:openstack:image_registry_and_delivery_service_\\(glance\\):2013.2.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "46675930-1B59-4379-8D53-65791B674633" }, { "criteria": "cpe:2.3:a:openstack:image_registry_and_delivery_service_\\(glance\\):2014.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D25939A0-128A-422D-8AA4-82ABF48701EE" }, { "criteria": "cpe:2.3:a:openstack:image_registry_and_delivery_service_\\(glance\\):2014.1.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "49917050-28EC-4C2E-B318-32108332AC4C" }, { "criteria": "cpe:2.3:a:openstack:image_registry_and_delivery_service_\\(glance\\):2014.1.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FF99F800-FFCA-423E-94DF-CF4E762B7E92" }, { "criteria": "cpe:2.3:a:openstack:image_registry_and_delivery_service_\\(glance\\):juno-1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "200CFA26-EBA7-425A-86EC-C13855382C6A" }, { "criteria": "cpe:2.3:a:openstack:image_registry_and_delivery_service_\\(glance\\):juno-2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8F3FFF72-B308-41EF-A807-255235CED49D" }, { "criteria": "cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*", "vulnerable": true, "matchCriteriaId": "B5A6F2F3-4894-4392-8296-3B8DD2679084" } ], "operator": "OR" } ] } ]