Description
In OpenStack Swift through 2.10.1, 2.11.0 through 2.13.0, and 2.14.0, the proxy-server logs full tempurl paths, potentially leaking reusable tempurl signatures to anyone with read access to these logs. All Swift deployments using the tempurl middleware are affected.
Related CPE's
a
openstack
swift
3
References
https://launchpad.net/bugs/1685798
Issue TrackingThird Party Advisory
https://launchpad.net/bugs/1685798
Issue TrackingThird Party Advisory
CVSS impact metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
4.3 · Medium
Information
Source identifier
Vulnerability status
Modified
Published
2021-06-02T12:15:07.753Z
4 years agoLast modified
2024-11-21T02:34:38.637Z
1 year ago