OSSA-2014-034: Swift metadata constraints are not correctly enforced

Date:

October 09, 2014

CVE:

CVE-2014-7960

Affects

  • Swift: up to 2.1.0

Description

Rajaneesh Singh reported a vulnerability in the way Swift enforces metadata constraints. By adding metadata in several separate calls, an authenticated attacker can bypass the max_meta_count constraint, potentially resulting in the storage of more metadata than allowed in configuration.

Patches

Credits

  • Rajaneesh Singh (CVE-2014-7960)

References