Comment 8 for bug 1498163

Revision history for this message
Tristan Cacqueray (tristan-cacqueray) wrote : Re: Glance storage quota bypass when token is expired

It seems like this could use an OSSA. However token lifetime is not user-controllable afaik... can the user tries more than 1 attempt per token expiration ?

Also the impact is different from OSSA-2015-003 if the left-over images are still located in the store.

Here is the proposed impact description.

Title: Glance storage overrun
Reporter: Mike Fedosin (Mirantis)
Products: Glance
Affects: versions through 2014.2.3 and 2015.1 versions through 2015.1.1

Description:
Mike Fedosin from Mirantis reported a vulnerability in Glance. By deleting images that are being uploaded using a token that is about to expire, a malicious user can overcome the storage quota and accumulate untracked image data in the backend resulting in potential resource exhaustion and denial of service. All Glance setups using the V1 API are affected and all setups using the V2 API with the registry db_api enabled are affected.