First published: Fri Oct 17 2014(Updated: )
OpenStack Object Storage (Swift) before 2.2.0 allows remote authenticated users to bypass the max_meta_count and other metadata constraints via multiple crafted requests which exceed the limit when combined.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
pip/swift | <2.2.0 | 2.2.0 |
OpenStack Swift3 | <=2.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-7960 is considered to have a medium severity due to its ability to allow authenticated users to bypass metadata constraints.
To fix CVE-2014-7960, upgrade to OpenStack Object Storage (Swift) version 2.2.0 or later.
CVE-2014-7960 affects OpenStack Object Storage (Swift) versions prior to 2.2.0.
No, CVE-2014-7960 can only be exploited by remote authenticated users.
The risks of CVE-2014-7960 include unauthorized overwriting of metadata constraints, which can lead to data integrity issues.