CVE-2015-1881: High severity Openstack Image Registry And Delivery Service \(glance\) vulnerability
OpenStack Image Registry and Delivery Service (Glance) 2014.2 through 2014.2.2 does not properly remove images, which allows remote authenticated users to cause a denial of service (disk consumption) by creating a large number of images using the task v2 API and then deleting them, a different vulnerability than CVE-2014-9684.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-1881?
CVE-2015-1881 has a moderate severity rating due to its potential for denial of service through disk consumption.
How do I fix CVE-2015-1881?
To remediate CVE-2015-1881, upgrade OpenStack Glance to version 11.0.0a0 or higher.
What versions of Glance are affected by CVE-2015-1881?
CVE-2015-1881 affects OpenStack Glance versions 2014.2 through 2014.2.2.
What type of vulnerability is CVE-2015-1881?
CVE-2015-1881 is a denial of service vulnerability allowing authenticated users to exhaust disk space.
Can CVE-2015-1881 be exploited remotely?
Yes, CVE-2015-1881 can be exploited by remote authenticated users.