Vulnerabilities
Vulnerable Software
Openstack:  >> Swift  Security Vulnerabilities
The TempURL middleware in OpenStack Object Storage (Swift) 1.4.6 through 1.8.0, 1.9.0 through 1.10.0, and 1.11.0 allows remote attackers to obtain secret URLs by leveraging an object name and a timing side-channel attack.
CVSS Score
4.3
EPSS Score
0.003
Published
2014-01-23
OpenStack Swift before 1.9.1 in Folsom, Grizzly, and Havana allows authenticated users to cause a denial of service ("superfluous" tombstone consumption and Swift cluster slowdown) via a DELETE request with a timestamp that is older than expected.
CVSS Score
4.0
EPSS Score
0.009
Published
2013-08-20
The v1 API in OpenStack Glance Essex (2012.1), Folsom (2012.2), and Grizzly, when using the single-tenant Swift or S3 store, reports the location field, which allows remote authenticated users to obtain the operator's backend credentials via a request for a cached image.
CVSS Score
3.5
EPSS Score
0.003
Published
2013-03-22
OpenStack Object Storage (swift) before 1.7.0 uses the loads function in the pickle Python module unsafely when storing and loading metadata in memcached, which allows remote attackers to execute arbitrary code via a crafted pickle object.
CVSS Score
9.8
EPSS Score
0.078
Published
2012-10-22


Contact Us

Shodan ® - All rights reserved