CVE-2015-1856
Published: 17 April 2015
OpenStack Object Storage (Swift) before 2.3.0, when allow_version is configured, allows remote authenticated users to delete the latest version of an object by leveraging listing access to the x-versions-location container.
Notes
Author | Note |
---|---|
mdeslaur | won't be fixed before 14.10 goes EoL |
jdstrand | requires allow_versions be set which is not available in 12.04 |
Priority
Status
Package | Release | Status |
---|---|---|
swift Launchpad, Ubuntu, Debian |
lucid |
Does not exist
|
precise |
Not vulnerable
(1.4.8-0ubuntu2.4)
|
|
trusty |
Released
(1.13.1-0ubuntu1.2)
|
|
upstream |
Needs triage
|
|
utopic |
Ignored
(end of life)
|
|
vivid |
Released
(2.2.2-0ubuntu1.3)
|
|
Patches: upstream: https://review.openstack.org/173366 upstream: https://review.openstack.org/173363 upstream: https://review.openstack.org/173361 |