Описание
OpenStack Object Storage (Swift) before 2.3.0, when allow_version is configured, allows remote authenticated users to delete the latest version of an object by leveraging listing access to the x-versions-location container.
A flaw was found in OpenStack Object Storage that could allow an authenticated user to delete the most recent version of a versioned object regardless of ownership. To exploit this flaw, an attacker must know the name of the object and have listing access to the x-versions-location container.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat OpenStack Platform 4 | openstack-swift | Will not fix | ||
| Native Client for RHEL 6 for Red Hat Storage | glusterfs | Fixed | RHSA-2015:1845 | 05.10.2015 |
| Native Client for RHEL 7 for Red Hat Storage | glusterfs | Fixed | RHSA-2015:1846 | 05.10.2015 |
| Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6 | openstack-swift | Fixed | RHSA-2015:1684 | 25.08.2015 |
| Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7 | openstack-swift | Fixed | RHSA-2015:1684 | 25.08.2015 |
| Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7 | openstack-swift | Fixed | RHSA-2015:1681 | 24.08.2015 |
| Red Hat Gluster Storage 3.1 for RHEL 6 | gdeploy | Fixed | RHSA-2015:1845 | 05.10.2015 |
| Red Hat Gluster Storage 3.1 for RHEL 6 | glusterfs | Fixed | RHSA-2015:1845 | 05.10.2015 |
| Red Hat Gluster Storage 3.1 for RHEL 6 | gluster-nagios-addons | Fixed | RHSA-2015:1845 | 05.10.2015 |
| Red Hat Gluster Storage 3.1 for RHEL 6 | gluster-nagios-common | Fixed | RHSA-2015:1845 | 05.10.2015 |
Показывать по
Дополнительная информация
Статус:
EPSS
3.5 Low
CVSS2
Связанные уязвимости
OpenStack Object Storage (Swift) before 2.3.0, when allow_version is configured, allows remote authenticated users to delete the latest version of an object by leveraging listing access to the x-versions-location container.
OpenStack Object Storage (Swift) before 2.3.0, when allow_version is configured, allows remote authenticated users to delete the latest version of an object by leveraging listing access to the x-versions-location container.
OpenStack Object Storage (Swift) before 2.3.0, when allow_version is c ...
OpenStack Swift Unauthorized delete of versioned Swift object
EPSS
3.5 Low
CVSS2