Comment 22 for bug 1365350

Revision history for this message
Thierry Carrez (ttx) wrote : Re: Metadata constraints defined in openstack documents doen't match implementation

Proposed impact description follows. Rajaneesh, do you want to credit a specific company, in addition to your name ?

Title: Swift metadata constraints are not correctly enforced
Reporter: Rajaneesh Singh (?)
Products: Swift
Versions: up to 2.1.0

Description:
Rajaneesh Singh from ? reported a vulnerability in Swift enforcement of metadata contraints. By adding metadata in several separate calls, an authenticated attacker can bypass the max_meta_count constraint, potentially resulting in the storage of more metadata than allowed in configuration.