CVE-2014-9623: Openstack Image Registry And Delivery Service (glance)

Medium severity, CVSS 4.0. EPSS: 2.9% chance of exploitation in the next 30 days.

OpenStack Glance 2014.2.x through 2014.2.1, 2014.1.3, and earlier allows remote authenticated users to bypass the storage quota and cause a denial of service (disk consumption) by deleting an image in the saving state.

Affected products

  • Openstack Image Registry And Delivery Service (glance): up to and including 2014.1.3; version 2014.2 only
  • Red Hat Openstack: version 5.0 only

Published 2015-01-23. Last modified 2026-06-17.