First published: Fri Aug 14 2015(Updated: )
OpenStack Glance before 2015.1.1 (kilo) allows remote authenticated users to cause a denial of service (disk consumption) by repeatedly using the import task flow API to create images and then deleting them.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Glance | <=2015.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-3289 has a medium severity rating as it allows remote authenticated users to cause denial of service through disk consumption.
To fix CVE-2015-3289, upgrade OpenStack Glance to version 2015.1.1 or later.
CVE-2015-3289 affects users of OpenStack Glance versions prior to 2015.1.1.
CVE-2015-3289 describes a denial of service attack that exploits the import task flow API to consume disk space.
No, CVE-2015-3289 can only be exploited by authenticated users of the OpenStack Glance service.