CVE-2014-8177: Medium severity red hat gluster storage management console vulnerability
Description: A flaw was found in the metadata constraints in gluster-swift package. By adding metadata in several separate calls, a malicious user could bypass the maxmetacount constraint, and store more metadata than allowed by the configuration.
References: http://seclists.org/oss-sec/2015/q3/448 https://review.openstack.org/#/c/215487
Other sources
The Red Hat gluster-swift package, as used in Red Hat Gluster Storage (formerly Red Hat Storage Server), allows remote authenticated users to bypass the maxmetacount constraint via multiple crafted requests which exceed the limit when combined.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-8177?
CVE-2014-8177 is classified as a medium severity vulnerability.
How do I fix CVE-2014-8177?
To fix CVE-2014-8177, update the gluster-swift package to the latest version provided by your vendor.
What versions are affected by CVE-2014-8177?
CVE-2014-8177 affects version 3.1 of the Red Hat Gluster Storage Management Console and Red Hat Gluster Storage Server.
Can CVE-2014-8177 lead to data loss?
Yes, CVE-2014-8177 could potentially lead to data loss due to unauthorized metadata storage.
Who is impacted by CVE-2014-8177?
Users of the affected Red Hat Gluster products are at risk from CVE-2014-8177.