{"id":"GHSA-gvjg-r9fv-7qx9","summary":"OpenStack Image Service (Glance) allows remote authenticated users to bypass storage quota, cause denial of service","details":"OpenStack Image Service (Glance) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) allows remote authenticated users to bypass the storage quota and cause a denial of service (disk consumption) by deleting images that are being uploaded using a token that expires during the process.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-9623.","aliases":["CVE-2015-5286","PYSEC-2026-812"],"modified":"2026-09-15T06:32:33.842934509Z","published":"2022-05-17T03:44:52Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2023-02-08T18:12:35Z","nvd_published_at":"2015-10-26T17:59:00Z","cwe_ids":["CWE-400"],"severity":"MODERATE"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2015-5286"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2015:1897"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2015-5286"},{"type":"WEB","url":"https://bugs.launchpad.net/bugs/1498163"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1267516"},{"type":"PACKAGE","url":"https://opendev.org/openstack/glance"},{"type":"WEB","url":"https://rhn.redhat.com/errata/RHSA-2015-1897.html"},{"type":"WEB","url":"https://security.openstack.org/ossa/OSSA-2015-020.html"},{"type":"WEB","url":"https://web.archive.org/web/20200228024859/http://www.securityfocus.com/bid/76943"}],"affected":[{"package":{"name":"glance","ecosystem":"PyPI","purl":"pkg:pypi/glance"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2014.2.4"}]}],"versions":["15.0.2","17.0.1","18.0.0","18.0.0.0b1","18.0.0.0rc1","18.0.1","19.0.0","19.0.0.0b1","19.0.0.0rc1","19.0.0.0rc2","19.0.1","19.0.2","19.0.3","19.0.4","20.0.0","20.0.0.0b1","20.0.0.0b2","20.0.0.0b3","20.0.0.0rc1","20.0.0.0rc2","20.0.1","20.1.0","20.2.0","21.0.0","21.0.0.0b1","21.0.0.0b2","21.0.0.0rc1","21.0.0.0rc2","21.1.0","22.0.0","22.0.0.0b2","22.0.0.0b3","22.0.0.0rc1","22.1.0","22.1.1","23.0.0","23.0.0.0b2","23.0.0.0b3","23.0.0.0rc1","23.0.0.0rc2","23.1.0","24.0.0","24.0.0.0rc1","24.1.0","24.2.0","24.2.1","25.0.0","25.0.0.0b2","25.0.0.0b3","25.0.0.0rc1","25.1.0","26.0.0","26.0.0.0b2","26.0.0.0b3","26.0.0.0rc1","26.1.0","27.0.0","27.0.0.0b1","27.0.0.0b2","27.0.0.0rc1","27.1.0","27.1.1","28.0.0","28.0.0.0b2","28.0.0.0rc1","28.0.1","28.1.0","28.2.0","29.0.0","29.0.0.0b1","29.0.0.0b2","29.0.0.0b3","29.0.0.0rc1","29.1.0","29.2.0","29.2.1","30.0.0","30.0.0.0b2","30.0.0.0rc1","30.1.0","30.2.0","31.0.0","31.0.0.0b2","31.0.0.0rc1","31.1.0","32.0.0","32.0.0.0b2","32.0.0.0rc1","32.0.0.0rc2","33.0.0.0b2","33.0.0.0rc1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-gvjg-r9fv-7qx9/GHSA-gvjg-r9fv-7qx9.json"}},{"package":{"name":"glance","ecosystem":"PyPI","purl":"pkg:pypi/glance"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2015.1.0"},{"fixed":"2015.1.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-gvjg-r9fv-7qx9/GHSA-gvjg-r9fv-7qx9.json"}}],"schema_version":"1.9.0"}