CVE-2014-7960
published 2014-10-17CVE-2014-7960: OpenStack Object Storage (Swift) before 2.2.0 allows remote authenticated users to bypass the max_meta_count and other metadata constraints via multiple…
PriorityP422medium4CVSS 2.0
AVNACLAuSCNIPAN
EPSS
3.02%
86.0th percentile
OpenStack Object Storage (Swift) before 2.2.0 allows remote authenticated users to bypass the max_meta_count and other metadata constraints via multiple crafted requests which exceed the limit when combined.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | swift | < swift 2.2.0-1 (bookworm) | swift 2.2.0-1 (bookworm) |
| openstack | swift | <= 2.1.0 | — |
| openstack | swift | >= 0 < 2.2.0-1 | 2.2.0-1 |
| openstack | swift | >= 0 < 2.2.0-1 | 2.2.0-1 |
| openstack | swift | >= 0 < 2.2.0-1 | 2.2.0-1 |
| openstack | swift | >= 0 < 2.2.0-1 | 2.2.0-1 |
| openstack | swift | >= 0 < 2.2.0 | 2.2.0 |
| openstack | swift | >= 0 < 1.13.1-0ubuntu1.2 | 1.13.1-0ubuntu1.2 |
CVSS provenance
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:N
osv4.0MEDIUM
vendor_debian4.0MEDIUM
vendor_redhat4.0MEDIUM
vendor_ubuntu4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
OpenStack Swift metadata constraints are not correctly enforced
osv·2022-05-17
CVE-2014-7960 [MEDIUM] OpenStack Swift metadata constraints are not correctly enforced
OpenStack Swift metadata constraints are not correctly enforced
OpenStack Object Storage (Swift) before 2.2.0 allows remote authenticated users to bypass the max_meta_count and other metadata constraints via multiple crafted requests which exceed the limit when combined.
GHSA
OpenStack Swift metadata constraints are not correctly enforced
ghsa·2022-05-17
CVE-2014-7960 [MEDIUM] OpenStack Swift metadata constraints are not correctly enforced
OpenStack Swift metadata constraints are not correctly enforced
OpenStack Object Storage (Swift) before 2.2.0 allows remote authenticated users to bypass the max_meta_count and other metadata constraints via multiple crafted requests which exceed the limit when combined.
OSV
swift vulnerabilities
osv·2015-08-06·CVSS 4.0
CVE-2014-7960 [MEDIUM] swift vulnerabilities
swift vulnerabilities
Rajaneesh Singh discovered Swift does not properly enforce metadata
limits. An attacker could abuse this issue to store more metadata than
allowed by policy. (CVE-2014-7960)
Clay Gerrard discovered Swift allowed users to delete the latest version
of object regardless of object permissions when allow_version is
configured. An attacker could use this issue to delete objects.
(CVE-2015-1856)
OSV
CVE-2014-7960: OpenStack Object Storage (Swift) before 2
osv·2014-10-17·CVSS 4.0
CVE-2014-7960 [MEDIUM] CVE-2014-7960: OpenStack Object Storage (Swift) before 2
OpenStack Object Storage (Swift) before 2.2.0 allows remote authenticated users to bypass the max_meta_count and other metadata constraints via multiple crafted requests which exceed the limit when combined.
Ubuntu
Swift vulnerabilities
vendor_ubuntu·2015-08-06·CVSS 4.0
CVE-2014-7960 [MEDIUM] Swift vulnerabilities
Title: Swift vulnerabilities
Summary: Several security issues were fixed in Swift.
Rajaneesh Singh discovered Swift does not properly enforce metadata
limits. An attacker could abuse this issue to store more metadata than
allowed by policy. (CVE-2014-7960)
Clay Gerrard discovered Swift allowed users to delete the latest version
of object regardless of object permissions when allow_version is
configured. An attacker could use this issue to delete objects.
(CVE-2015-1856)
Instructions: After a standard system update you need to restart swift to make
all the necessary changes.
Red Hat
openstack-swift: Swift metadata constraints are not correctly enforced
vendor_redhat·2014-09-04·CVSS 4.0
CVE-2014-7960 [MEDIUM] CWE-400 openstack-swift: Swift metadata constraints are not correctly enforced
openstack-swift: Swift metadata constraints are not correctly enforced
OpenStack Object Storage (Swift) before 2.2.0 allows remote authenticated users to bypass the max_meta_count and other metadata constraints via multiple crafted requests which exceed the limit when combined.
A flaw was found in the metadata constraints in OpenStack Object Storage (swift). By adding metadata in several separate calls, a malicious user could bypass the max_meta_count constraint, and store more metadata than allowed by the configuration.
Package: openstack-swift (Red Hat OpenStack Platform 4) - Will not fix
Debian
CVE-2014-7960: swift - OpenStack Object Storage (Swift) before 2.2.0 allows remote authenticated users ...
vendor_debian·2014·CVSS 4.0
CVE-2014-7960 [MEDIUM] CVE-2014-7960: swift - OpenStack Object Storage (Swift) before 2.2.0 allows remote authenticated users ...
OpenStack Object Storage (Swift) before 2.2.0 allows remote authenticated users to bypass the max_meta_count and other metadata constraints via multiple crafted requests which exceed the limit when combined.
Scope: local
bookworm: resolved (fixed in 2.2.0-1)
bullseye: resolved (fixed in 2.2.0-1)
forky: resolved (fixed in 2.2.0-1)
sid: resolved (fixed in 2.2.0-1)
trixie: resolved (fixed in 2.2.0-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-7960 openstack-swift: Swift metadata constraints are not correctly enforced
bugzilla·2014-10-08·CVSS 4.0
CVE-2014-7960 [MEDIUM] CVE-2014-7960 openstack-swift: Swift metadata constraints are not correctly enforced
CVE-2014-7960 openstack-swift: Swift metadata constraints are not correctly enforced
The following was reported to oss-sec:
Title: Swift metadata constraints are not correctly enforced
Reporter: Rajaneesh Singh
Products: Swift
Versions: up to 2.1.0
Description:
Rajaneesh Singh reported a vulnerability in Swift enforcement of
metadata contraints. By adding metadata in several separate calls,
an authenticated attacker can bypass the max_meta_count constraint,
potentially resulting in the storage of more metadata than allowed
in configuration.
References:
https://launchpad.net/bugs/1365350
http://seclists.org/oss-sec/2014/q4/205
Discussion:
Created openstack-swift tracking bugs for this issue:
Affects: fedora-all [bug 1150782]
---
This issue has been addressed in the following produc
Bugzilla
CVE-2014-7960 openstack-swift: Swift metadata constraints are not correctly enforced [fedora-all]
bugzilla·2014-10-08·CVSS 4.0
CVE-2014-7960 [MEDIUM] CVE-2014-7960 openstack-swift: Swift metadata constraints are not correctly enforced [fedora-all]
CVE-2014-7960 openstack-swift: Swift metadata constraints are not correctly enforced [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple su
http://lists.opensuse.org/opensuse-security-announce/2015-10/msg00025.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0835.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0836.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1495.htmlhttp://www.openwall.com/lists/oss-security/2014/10/07/39http://www.openwall.com/lists/oss-security/2014/10/08/7http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.htmlhttp://www.securityfocus.com/bid/70279http://www.ubuntu.com/usn/USN-2704-1https://bugs.launchpad.net/swift/+bug/1365350https://exchange.xforce.ibmcloud.com/vulnerabilities/96901http://lists.opensuse.org/opensuse-security-announce/2015-10/msg00025.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0835.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0836.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1495.htmlhttp://www.openwall.com/lists/oss-security/2014/10/07/39http://www.openwall.com/lists/oss-security/2014/10/08/7http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.htmlhttp://www.securityfocus.com/bid/70279http://www.ubuntu.com/usn/USN-2704-1https://bugs.launchpad.net/swift/+bug/1365350https://exchange.xforce.ibmcloud.com/vulnerabilities/96901
2014-10-17
Published