Bug 1243927 (CVE-2015-3289)

Summary: CVE-2015-3289 openstack-glance: potential resource exhaustion task flow API
Product: [Other] Security Response Reporter: Martin Prpič <mprpic>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED NOTABUG QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: abaron, aortega, apevec, ayoung, chrisw, dallan, eglynn, fpercoco, gkotton, gmollett, lhh, lpeer, markmc, rbryant, sclewis, security-response-team, tdecacqu, yeylon
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2015-07-29 02:33:35 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1244033, 1247826    
Bug Blocks: 1243928    

Description Martin Prpič 2015-07-16 15:27:24 UTC
By creating numerous images using the import task flow API and deleting them, an authenticated attacker may accumulate untracked image data in the backend resulting in potential resource exhaustion and denial of service.

Proposed patches:

master - https://review.openstack.org/#/c/181345/
kilo - https://review.openstack.org/#/c/181816/

Comment 2 Garth Mollett 2015-07-19 23:20:41 UTC
Statement:

This issue does not affect any versions of openstack-glance as shipped with any currently supported releases of Red Hat Enterprise Linux OpenStack Platform.

Comment 3 Garth Mollett 2015-07-29 02:31:17 UTC
Created openstack-glance tracking bugs for this issue:

Affects: openstack-rdo [bug 1247826]