CVE-2014-7960
OpenStack Swift metadata constraints are not correctly enforced
EPSS 0.34%
Description
OpenStack Object Storage (Swift) before 2.2.0 allows remote authenticated users to bypass the max_meta_count and other metadata constraints via multiple crafted requests which exceed the limit when combined.
How to fix CVE-2014-7960
To remediate CVE-2014-7960, upgrade the affected package to a fixed version below.
- Debian/swift—upgrade to 2.2.0-1 or later
- PyPI/swift—upgrade to 2.2.0 or later
Is CVE-2014-7960 being exploited?
Low — EPSS is 0.3%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 2.2.0-1
- from 0, < 2.2.0