VDB
CVE-2014-9684
CVE-2014-9684
PUBLISHED
CVSS 4 MEDIUM
OpenStack Glance Denial of service by creating a large number of images
EPSS 0.58% · 69.3th percentile
Risk Scores
CVSS 2.0
4
EPSS Score
0.58%
69.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| PyPI | glance | 0 |
| n/a | n/a | n/a |
| openstack | image_registry_and_delivery_service_\(glance\) | 2014.2, 2014.2.1, 2014.2.2 |
Timeline
- Feb 24, 2015 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 3, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 8, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Jul 16, 2023 EPSS Score
- Sep 7, 2023 EPSS Score
References
- http://www.securityfocus.com/bid/72692 technical
- [openstack-announce] 20150223 [OSSA 2015-004] Glance import task leaks image in backend (CVE-2014-9684, CVE-2015-1881) mailing-list
- https://bugs.launchpad.net/glance/+bug/1371118 url
- RHSA-2015:0938 vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2014-9684 advisory
- https://github.com/openstack/glance/commit/7858d4d95154c8596720365e465cca7858cfec5c url
- https://github.com/openstack/glance/commit/a880c8e762e94b70c1e5d5692a3defcde734a601 url
- https://github.com/openstack/glance package
- https://github.com/pypa/advisory-database/tree/main/vulns/glance/PYSEC-2015-37.yaml url