CVE-2014-9623
OpenStack Glance Bypass the storage quota and Denial of service
EPSS 0.30%
Description
OpenStack Glance 2014.2.x through 2014.2.1, 2014.1.3, and earlier allows remote authenticated users to bypass the storage quota and cause a denial of service (disk consumption) by deleting an image in the saving state.
How to fix CVE-2014-9623
To remediate CVE-2014-9623, upgrade the affected package to a fixed version below.
- Debian/glance—upgrade to 2014.1.3-12 or later
- PyPI/glance—upgrade to 11.0.0a0 or later
Is CVE-2014-9623 being exploited?
Low — EPSS is 0.3%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 2014.1.3-12
- from 0, < 11.0.0a0