Описание
In OpenStack Swift through 2.10.1, 2.11.0 through 2.13.0, and 2.14.0, the proxy-server logs full tempurl paths, potentially leaking reusable tempurl signatures to anyone with read access to these logs. All Swift deployments using the tempurl middleware are affected.
A flaw was found in openstack-swift, where the proxy server logs valid temporary URLs, that might be used to gain access to data by anyone with access to the logfiles. This is especially important with tempurls that are valid for extended periods or when using central logging servers, accessed by operators that have no access to the Swift servers. The highest threat from this vulnerability is to confidentiality.
Отчет
Openstack Swift is no longer supported with the recent release of Red Hat Gluster Storage 3.5, hence openstack-swift will not be updated for this flaw.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat JBoss Fuse 6 | openstack-swift | Out of support scope | ||
| Red Hat OpenStack Platform 10 (Newton) | openstack-swift | Out of support scope | ||
| Red Hat OpenStack Platform 13 (Queens) | openstack-swift | Fix deferred | ||
| Red Hat OpenStack Platform 15 (Stein) | openstack-swift | Fix deferred | ||
| Red Hat OpenStack Platform 16.1 | openstack-swift | Fix deferred | ||
| Red Hat OpenStack Platform 16.2 | openstack-swift | Fix deferred | ||
| Red Hat OpenStack Platform 16 (Train) | openstack-swift | Fix deferred | ||
| Red Hat Storage 3 | openstack-swift | Out of support scope |
Показывать по
Дополнительная информация
Статус:
2.2 Low
CVSS3
Связанные уязвимости
In OpenStack Swift through 2.10.1, 2.11.0 through 2.13.0, and 2.14.0, the proxy-server logs full tempurl paths, potentially leaking reusable tempurl signatures to anyone with read access to these logs. All Swift deployments using the tempurl middleware are affected.
In OpenStack Swift through 2.10.1, 2.11.0 through 2.13.0, and 2.14.0, the proxy-server logs full tempurl paths, potentially leaking reusable tempurl signatures to anyone with read access to these logs. All Swift deployments using the tempurl middleware are affected.
In OpenStack Swift through 2.10.1, 2.11.0 through 2.13.0, and 2.14.0, ...
Уязвимость логов proxy-сервера промежуточного ПО tempurl распределенной системы хранения объектов Swift, связанная с раскрытием информации, позволяющая нарушителю получить доступ к конфиденциальным данным
2.2 Low
CVSS3