cbcvebase.
CVE-2014-7960
published 2014-10-17

CVE-2014-7960: OpenStack Object Storage (Swift) before 2.2.0 allows remote authenticated users to bypass the max_meta_count and other metadata constraints via multiple…

PriorityP422medium4CVSS 2.0
AVNACLAuSCNIPAN
EPSS
3.02%
86.0th percentile
OpenStack Object Storage (Swift) before 2.2.0 allows remote authenticated users to bypass the max_meta_count and other metadata constraints via multiple crafted requests which exceed the limit when combined.

Affected

8 ranges
VendorProductVersion rangeFixed in
debianswift< swift 2.2.0-1 (bookworm)swift 2.2.0-1 (bookworm)
openstackswift<= 2.1.0
openstackswift>= 0 < 2.2.0-12.2.0-1
openstackswift>= 0 < 2.2.0-12.2.0-1
openstackswift>= 0 < 2.2.0-12.2.0-1
openstackswift>= 0 < 2.2.0-12.2.0-1
openstackswift>= 0 < 2.2.02.2.0
openstackswift>= 0 < 1.13.1-0ubuntu1.21.13.1-0ubuntu1.2

CVSS provenance

nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:N
osv4.0MEDIUM
vendor_debian4.0MEDIUM
vendor_redhat4.0MEDIUM
vendor_ubuntu4.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.