CVE-2014-8177

Related Vulnerabilities: CVE-2014-8177  

A flaw was found in the metadata constraints in Red Hat Gluster Storage's OpenStack Object Storage (swiftonfile). By adding metadata in several separate calls, a malicious user could bypass the max_meta_count constraint, and store more metadata than allowed by the configuration.

A flaw was found in the metadata constraints in Red Hat Gluster Storage's OpenStack Object Storage (swiftonfile). By adding metadata in several separate calls, a malicious user could bypass the max_meta_count constraint, and store more metadata than allowed by the configuration.

Find out more about CVE-2014-8177 from the MITRE CVE dictionary dictionary and NIST NVD.

CVSS v2 metrics

Base Score 4
Base Metrics AV:N/AC:L/Au:S/C:N/I:N/A:P
Access Vector Network
Access Complexity Low
Authentication Single
Confidentiality Impact None
Integrity Impact None
Availability Impact Partial

Find out more about Red Hat support for the Common Vulnerability Scoring System (CVSS).

Red Hat Security Errata

Platform Errata Release Date
Red Hat Storage Native Client for Red Hat Enterprise Linux 7 (glusterfs) RHSA-2015:1846 2015-10-05
Red Hat Gluster Storage NFS 3.1 on RHEL-6 (nfs-ganesha) RHSA-2015:1845 2015-10-05
Red Hat Gluster Storage Server 3.1 on RHEL-6 (swiftonfile) RHSA-2015:1845 2015-10-05
Red Hat Gluster Storage Nagios 3.1 on RHEL-6 RHSA-2015:1845 2015-10-05
Red Hat Storage Native Client for Red Hat Enterprise Linux 6 (glusterfs) RHSA-2015:1845 2015-10-05
Red Hat Gluster Storage NFS 3.1 on RHEL-7 (nfs-ganesha) RHSA-2015:1846 2015-10-05
Red Hat Gluster Storage Server 3.1 on RHEL-7 (swiftonfile) RHSA-2015:1846 2015-10-05
Red Hat Gluster Storage Nagios 3.1 on RHEL-7 RHSA-2015:1846 2015-10-05