CVE-2015-1856
Published: 17 April 2015
OpenStack Object Storage (Swift) before 2.3.0, when allow_version is configured, allows remote authenticated users to delete the latest version of an object by leveraging listing access to the x-versions-location container.
Notes
| Author | Note |
|---|---|
| mdeslaur | won't be fixed before 14.10 goes EoL |
| jdstrand | requires allow_versions be set which is not available in 12.04 |
Priority
Status
| Package | Release | Status |
|---|---|---|
|
swift Launchpad, Ubuntu, Debian |
lucid |
Does not exist
|
| precise |
Not vulnerable
(1.4.8-0ubuntu2.4)
|
|
| trusty |
Released
(1.13.1-0ubuntu1.2)
|
|
| upstream |
Needs triage
|
|
| utopic |
Ignored
(end of life)
|
|
| vivid |
Released
(2.2.2-0ubuntu1.3)
|
|
|
Patches: upstream: https://review.openstack.org/173366 upstream: https://review.openstack.org/173363 upstream: https://review.openstack.org/173361 |
||