MEDIUM · 4.0

CVE-2014-7960

OpenStack Object Storage (Swift) before 2.2.0 allows remote authenticated users to bypass the max_meta_count and other metadata constraints via multiple crafted requests which exceed the limit when co...

Vulnerability Description

OpenStack Object Storage (Swift) before 2.2.0 allows remote authenticated users to bypass the max_meta_count and other metadata constraints via multiple crafted requests which exceed the limit when combined.

CVSS Score

4.0

MEDIUM

AV:N/AC:L/Au:S/C:N/I:P/A:N
Confidentiality
NONE
Integrity
PARTIAL
Availability
NONE

Affected Products

VendorProductVersions
OpenstackSwift<= 2.1.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2014-7960?

CVE-2014-7960 is a vulnerability with a CVSS score of 4.0 (MEDIUM). OpenStack Object Storage (Swift) before 2.2.0 allows remote authenticated users to bypass the max_meta_count and other metadata constraints via multiple crafted requests which exceed the limit when co...

How severe is CVE-2014-7960?

CVE-2014-7960 has been rated MEDIUM with a CVSS base score of 4.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2014-7960?

Check the references section above for vendor advisories and patch information. Affected products include: Openstack Swift.