Comment 17 for bug 1420696

Revision history for this message
Tristan Cacqueray (tristan-cacqueray) wrote : Re: Image data remains in backend after deleting the image created using task api (import-from)

Oh and thanks for the impact description review, here is an update with proper affected versions:

Title: Glance import task leaks image in backend
Reporter: Abhishek Kekane (NTT)
Products: Glance
Affects: 2014.2 versions through 2014.2.2

Description:
Abhishek Kekane from NTT reported a vulnerability in the Glance import task. By creating numerous images using the task API and deleting them, an authenticated attacker may leaks images data in the backend resulting in potential resources exhaustion and denial of service. All glance setups are affected.