MEDIUM · 4.0

CVE-2014-9623

OpenStack Glance 2014.2.x through 2014.2.1, 2014.1.3, and earlier allows remote authenticated users to bypass the storage quota and cause a denial of service (disk consumption) by deleting an image in...

Vulnerability Description

OpenStack Glance 2014.2.x through 2014.2.1, 2014.1.3, and earlier allows remote authenticated users to bypass the storage quota and cause a denial of service (disk consumption) by deleting an image in the saving state.

CVSS Score

4.0

MEDIUM

AV:N/AC:L/Au:S/C:N/I:N/A:P
Confidentiality
NONE
Integrity
NONE
Availability
PARTIAL

Affected Products

VendorProductVersions
RedhatOpenstack5.0
OpenstackImage Registry And Delivery Service \(Glance\)<= 2014.1.3

Related Weaknesses (CWE)

References

FAQ

What is CVE-2014-9623?

CVE-2014-9623 is a vulnerability with a CVSS score of 4.0 (MEDIUM). OpenStack Glance 2014.2.x through 2014.2.1, 2014.1.3, and earlier allows remote authenticated users to bypass the storage quota and cause a denial of service (disk consumption) by deleting an image in...

How severe is CVE-2014-9623?

CVE-2014-9623 has been rated MEDIUM with a CVSS base score of 4.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2014-9623?

Check the references section above for vendor advisories and patch information. Affected products include: Redhat Openstack, Openstack Image Registry And Delivery Service \(Glance\).