Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-5242

Опубликовано: 20 окт. 2015
Источник: redhat
CVSS2: 6
EPSS Низкий

Описание

OpenStack Swift-on-File (aka Swiftonfile) does not properly restrict use of the pickle Python module when loading metadata, which allows remote authenticated users to execute arbitrary code via a crafted extended attribute (xattrs).

A flaw was found in the way swiftonfile (gluster-swift) serialized and stored metadata on disk by using Python's pickle module. A remote, authenticated user could use this flaw to execute arbitrary code on the storage node.

Дополнительная информация

Статус:

Important
https://bugzilla.redhat.com/show_bug.cgi?id=1258743swiftonfile: use of insecure Python pickle for metadata serialization and storage

EPSS

Процентиль: 79%
0.01202
Низкий

6 Medium

CVSS2

Связанные уязвимости

nvd
около 10 лет назад

OpenStack Swift-on-File (aka Swiftonfile) does not properly restrict use of the pickle Python module when loading metadata, which allows remote authenticated users to execute arbitrary code via a crafted extended attribute (xattrs).

github
больше 3 лет назад

OpenStack Swift-on-File (aka Swiftonfile) does not properly restrict use of the pickle Python module when loading metadata, which allows remote authenticated users to execute arbitrary code via a crafted extended attribute (xattrs).

EPSS

Процентиль: 79%
0.01202
Низкий

6 Medium

CVSS2