Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-8177

Опубликовано: 21 авг. 2015
Источник: redhat
CVSS2: 4
EPSS Низкий

Описание

The Red Hat gluster-swift package, as used in Red Hat Gluster Storage (formerly Red Hat Storage Server), allows remote authenticated users to bypass the max_meta_count constraint via multiple crafted requests which exceed the limit when combined.

A flaw was found in the metadata constraints in Red Hat Gluster Storage's OpenStack Object Storage (swiftonfile). By adding metadata in several separate calls, a malicious user could bypass the max_meta_count constraint, and store more metadata than allowed by the configuration.

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=1257525gluster-swift metadata constraints are not correctly enforced

EPSS

Процентиль: 31%
0.00116
Низкий

4 Medium

CVSS2

Связанные уязвимости

CVSS3: 6.5
nvd
больше 9 лет назад

The Red Hat gluster-swift package, as used in Red Hat Gluster Storage (formerly Red Hat Storage Server), allows remote authenticated users to bypass the max_meta_count constraint via multiple crafted requests which exceed the limit when combined.

CVSS3: 6.5
github
больше 3 лет назад

The Red Hat gluster-swift package, as used in Red Hat Gluster Storage (formerly Red Hat Storage Server), allows remote authenticated users to bypass the max_meta_count constraint via multiple crafted requests which exceed the limit when combined.

EPSS

Процентиль: 31%
0.00116
Низкий

4 Medium

CVSS2