Description
OpenStack Image Registry and Delivery Service (Glance) before 2013.2.4, 2014.x before 2014.1.3, and Juno before Juno-3, when using the V2 API, does not properly enforce the image_size_cap configuration option, which allows remote authenticated users to cause a denial of service (disk consumption) by uploading a large image.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-2324 | OpenStack Image Registry and Delivery Service (Glance) before 2013.2.4, 2014.x before 2014.1.3, and Juno before Juno-3, when using the V2 API, does not properly enforce the image_size_cap configuration option, which allows remote authenticated users to cause a denial of service (disk consumption) by uploading a large image. |
Github GHSA |
GHSA-479j-jf2p-38pg | OpenStack Glance improper validation of the image_size_cap configuration option |
Ubuntu USN |
USN-2322-1 | OpenStack Glance vulnerability |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-06T11:41:49.236Z
Reserved: 2014-08-19T00:00:00.000Z
Link: CVE-2014-5356
No data.
Status : Modified
Published: 2014-08-25T14:55:07.160
Modified: 2026-05-06T22:30:45.220
Link: CVE-2014-5356
OpenCVE Enrichment
No data.
EUVD
Github GHSA
Ubuntu USN