CVE-2015-3289: Medium severity openstack glance store vulnerability
Published Aug 14, 2015
·Updated
OpenStack Glance before 2015.1.1 (kilo) allows remote authenticated users to cause a denial of service (disk consumption) by repeatedly using the import task flow API to create images and then deleting them.
Affected Software
1 affected component
Openstack Glance<=2015.1.0
Remediation
Patch Available
Event History
Aug 14, 2015
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-3289?
CVE-2015-3289 has a medium severity rating as it allows remote authenticated users to cause denial of service through disk consumption.
2
How do I fix CVE-2015-3289?
To fix CVE-2015-3289, upgrade OpenStack Glance to version 2015.1.1 or later.
3
Who is affected by CVE-2015-3289?
CVE-2015-3289 affects users of OpenStack Glance versions prior to 2015.1.1.
4
What type of attack does CVE-2015-3289 describe?
CVE-2015-3289 describes a denial of service attack that exploits the import task flow API to consume disk space.
5
Can CVE-2015-3289 be exploited without authentication?
No, CVE-2015-3289 can only be exploited by authenticated users of the OpenStack Glance service.