CVE Vulnerabilities

CVE-2014-7960

Published: Oct 17, 2014 | Modified: Sep 08, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:N/I:P/A:N
RedHat/V2
4 MODERATE
AV:N/AC:L/Au:S/C:N/I:N/A:P
RedHat/V3
Ubuntu
LOW

OpenStack Object Storage (Swift) before 2.2.0 allows remote authenticated users to bypass the max_meta_count and other metadata constraints via multiple crafted requests which exceed the limit when combined.

Affected Software

Name Vendor Start Version End Version
Swift Openstack * 2.1.0 (including)
Native Client for RHEL 5 for Red Hat Storage RedHat glusterfs-0:3.7.1-11.el5 *
Native Client for RHEL 6 for Red Hat Storage RedHat glusterfs-0:3.7.1-11.el6 *
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6 RedHat openstack-swift-0:1.13.1-4.el6ost *
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7 RedHat openstack-swift-0:1.13.1-4.el7ost *
Red Hat Gluster Storage 3.1 for RHEL 6 RedHat augeas-0:1.0.0-10.el6 *
Red Hat Gluster Storage 3.1 for RHEL 6 RedHat check-mk-0:1.2.6p1-3.el6rhs *
Red Hat Gluster Storage 3.1 for RHEL 6 RedHat clufter-0:0.11.2-1.el6 *
Red Hat Gluster Storage 3.1 for RHEL 6 RedHat cluster-0:3.0.12.1-73.el6 *
Red Hat Gluster Storage 3.1 for RHEL 6 RedHat clustermon-0:0.16.2-31.el6 *
Red Hat Gluster Storage 3.1 for RHEL 6 RedHat corosync-0:1.4.7-2.el6 *
Red Hat Gluster Storage 3.1 for RHEL 6 RedHat ctdb2.5-0:2.5.5-7.el6rhs *
Red Hat Gluster Storage 3.1 for RHEL 6 RedHat fence-virt-0:0.2.3-19.el6 *
Red Hat Gluster Storage 3.1 for RHEL 6 RedHat glusterfs-0:3.7.1-11.el6rhs *
Red Hat Gluster Storage 3.1 for RHEL 6 RedHat gluster-nagios-addons-0:0.2.4-4.el6rhs *
Red Hat Gluster Storage 3.1 for RHEL 6 RedHat gluster-nagios-common-0:0.2.0-1.el6rhs *
Red Hat Gluster Storage 3.1 for RHEL 6 RedHat gstatus-0:0.64-3.1.el6rhs *
Red Hat Gluster Storage 3.1 for RHEL 6 RedHat libqb-0:0.17.1-1.el6 *
Red Hat Gluster Storage 3.1 for RHEL 6 RedHat libtalloc-0:2.1.1-4.el6rhs *
Red Hat Gluster Storage 3.1 for RHEL 6 RedHat libvirt-0:0.10.2-54.el6 *
Red Hat Gluster Storage 3.1 for RHEL 6 RedHat nagios-plugins-0:1.4.16-12.el6rhs *
Red Hat Gluster Storage 3.1 for RHEL 6 RedHat nagios-server-addons-0:0.2.1-4.el6rhs *
Red Hat Gluster Storage 3.1 for RHEL 6 RedHat nfs-ganesha-0:2.2.0-5.el6rhs *
Red Hat Gluster Storage 3.1 for RHEL 6 RedHat nrpe-0:2.15-4.1.el6rhs *
Red Hat Gluster Storage 3.1 for RHEL 6 RedHat openais-0:1.1.1-7.el6 *
Red Hat Gluster Storage 3.1 for RHEL 6 RedHat openstack-swift-0:1.13.1-4.el6ost *
Red Hat Gluster Storage 3.1 for RHEL 6 RedHat pacemaker-0:1.1.12-8.el6 *
Red Hat Gluster Storage 3.1 for RHEL 6 RedHat pcs-0:0.9.139-9.el6 *
Red Hat Gluster Storage 3.1 for RHEL 6 RedHat pnp4nagios-0:0.6.22-2.1.el6rhs *
Red Hat Gluster Storage 3.1 for RHEL 6 RedHat pynag-0:0.9.1-1.el6rhs *
Red Hat Gluster Storage 3.1 for RHEL 6 RedHat python-blivet-1:1.0.0.2-1.el6rhs *
Red Hat Gluster Storage 3.1 for RHEL 6 RedHat python-cpopen-0:1.3-4.el6_5 *
Red Hat Gluster Storage 3.1 for RHEL 6 RedHat python-eventlet-0:0.14.0-1.el6 *
Red Hat Gluster Storage 3.1 for RHEL 6 RedHat python-greenlet-0:0.4.2-1.el6 *
Red Hat Gluster Storage 3.1 for RHEL 6 RedHat python-keystoneclient-1:0.9.0-5.el6ost *
Red Hat Gluster Storage 3.1 for RHEL 6 RedHat python-prettytable-0:0.7.2-1.el6 *
Red Hat Gluster Storage 3.1 for RHEL 6 RedHat python-pyudev-0:0.15-2.el6rhs *
Red Hat Gluster Storage 3.1 for RHEL 6 RedHat redhat-storage-logos-0:60.0.20-1.el6rhs *
Red Hat Gluster Storage 3.1 for RHEL 6 RedHat redhat-storage-server-0:3.1.0.3-1.el6rhs *
Red Hat Gluster Storage 3.1 for RHEL 6 RedHat resource-agents-0:3.9.5-24.el6 *
Red Hat Gluster Storage 3.1 for RHEL 6 RedHat ricci-0:0.16.2-81.el6 *
Red Hat Gluster Storage 3.1 for RHEL 6 RedHat userspace-rcu-0:0.7.9-2.el6rhs *
Red Hat Gluster Storage 3.1 for RHEL 6 RedHat vdsm-0:4.16.20-1.2.el6rhs *
Swift Ubuntu precise *
Swift Ubuntu trusty *
Swift Ubuntu upstream *
Swift Ubuntu utopic *
Swift Ubuntu vivid *

References