USN-2256-1: Swift vulnerability
25 June 2014
Swift did not properly perform input validation of certain HTTP headers.
- swift - OpenStack distributed virtual object store
John Dickinson discovered that Swift did not properly quote the
WWW-Authenticate header value. If a user were tricked into navigating to a
malicious Swift URL, an attacker could conduct cross-site scripting
attacks. With cross-site scripting vulnerabilities, if a user were tricked
into viewing server output during a crafted server request, a remote
attacker could exploit this to modify the contents, or steal confidential
data, within the same domain.