Skip to content

CVE-2014-5356

OpenStack Image Registry and Delivery Service (Glance) before 2013.2.4, 2014.x before 2014.1.3, and Juno before Juno-3, when using the V2 API, does not properly enforce the image_size_cap configuration option, which allows remote authenticated users to cause a denial of service (disk consumption) by uploading a large image.

View on NVD

Severity

N/A

EPSS

Probability of exploitation (next 30 days): 0.0080 (0.8%)
Percentile: 74.2%
EPSS: 2026-05-06

Affects

openstack:image_registry_and_delivery_service_\(glance\)canonical:ubuntu_linux

Technical description

OpenStack Image Registry and Delivery Service (Glance) before 2013.2.4, 2014.x before 2014.1.3, and Juno before Juno-3, when using the V2 API, does not properly enforce the image_size_cap configuration option, which allows remote authenticated users to cause a denial of service (disk consumption) by uploading a large image.

Published: 8/25/2014, 2:55:07 PM
Last modified: 5/6/2026, 10:30:45 PM

References

HomeEventsBlogResourcesTeam