Comment 16 for bug 1498163

Revision history for this message
Tristan Cacqueray (tristan-cacqueray) wrote : Re: Glance storage quota bypass when token is expired

Jeremy, I'd like to keep the proposed impact description, the title seems correct to me since the left-over image remain in the backend. This is actually worst than bug 1398830 (for OSSA 2015-003) where left-over image are actually deleted after the upload finished iiuc.

Here is an update impact description to include the additional reporter and new affected version line:

Title: Glance storage overrun
Reporter: Mike Fedosin and Alexei Galkin (Mirantis)
Products: Glance
Affects: <=2014.2.3, >=2015.1.0, <=2015.1.1

Description:
Mike Fedosin and Alexei Galkin from Mirantis reported a vulnerability in Glance. By deleting images that are being uploaded using a token that is about to expire, a malicious user can overcome the storage quota and accumulate untracked image data in the backend resulting in potential resource exhaustion and denial of service. All Glance setups using the V1 API are affected and all setups using the V2 API with the registry db_api enabled are affected.