CVE-2014-5356: Medium severity openstack glance vulnerability
OpenStack Image Registry and Delivery Service (Glance) before 2013.2.4, 2014.x before 2014.1.3, and Juno before Juno-3, when using the V2 API, does not properly enforce the imagesizecap configuration option, which allows remote authenticated users to cause a denial of service (disk consumption) by uploading a large image.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-5356?
CVE-2014-5356 has a medium severity level as it can lead to denial of service due to disk consumption.
How do I fix CVE-2014-5356?
To fix CVE-2014-5356, upgrade to OpenStack Glance version 2013.2.4, 2014.1.3, or Juno-3 or later.
Which versions of OpenStack Glance are affected by CVE-2014-5356?
OpenStack Glance versions before 2013.2.4, 2014.x before 2014.1.3, and Juno before Juno-3 are affected by CVE-2014-5356.
What vulnerability does CVE-2014-5356 exploit?
CVE-2014-5356 exploits a failure to enforce the image_size_cap configuration option in the V2 API.
Can CVE-2014-5356 be exploited by remote users?
Yes, CVE-2014-5356 can be exploited by remote authenticated users causing denial of service.