Moderate severityNVD Advisory· Published Oct 26, 2015· Updated May 6, 2026
CVE-2015-5286
CVE-2015-5286
Description
OpenStack Image Service (Glance) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) allows remote authenticated users to bypass the storage quota and cause a denial of service (disk consumption) by deleting images that are being uploaded using a token that expires during the process. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-9623.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
glancePyPI | < 2014.2.4 | 2014.2.4 |
glancePyPI | >= 2015.1.0, < 2015.1.2 | 2015.1.2 |
Affected products
3- ghsa-coords3 versionspkg:pypi/glancepkg:rpm/suse/openstack-glance&distro=SUSE%20OpenStack%20Cloud%205pkg:rpm/suse/openstack-glance-doc&distro=SUSE%20OpenStack%20Cloud%205
< 2014.2.4+ 2 more
- (no CPE)range: < 2014.2.4
- (no CPE)range: < 2014.2.4.juno-14.1
- (no CPE)range: < 2014.2.4.juno-14.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
12- github.com/advisories/GHSA-gvjg-r9fv-7qx9ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2015-5286ghsaADVISORY
- security.openstack.org/ossa/OSSA-2015-020.htmlnvdVendor AdvisoryWEB
- access.redhat.com/errata/RHSA-2015:1897ghsaWEB
- access.redhat.com/security/cve/CVE-2015-5286ghsaWEB
- bugs.launchpad.net/bugs/1498163nvdWEB
- bugzilla.redhat.com/show_bug.cgighsaWEB
- opendev.org/openstack/glanceghsaPACKAGE
- rhn.redhat.com/errata/RHSA-2015-1897.htmlghsaWEB
- web.archive.org/web/20200228024859/http://www.securityfocus.com/bid/76943ghsaWEB
- rhn.redhat.com/errata/RHSA-2015-1897.htmlnvd
- www.securityfocus.com/bid/76943nvd
News mentions
0No linked articles in our index yet.