Swift3 before 1.9 allows remote attackers to conduct replay attacks via an Authorization request that lacks a Date header.
References
Configurations
History
21 Nov 2024, 02:38
Type | Values Removed | Values Added |
---|---|---|
References | () http://lists.fedoraproject.org/pipermail/package-announce/2015-December/174374.html - Patch | |
References | () http://www.debian.org/security/2016/dsa-3583 - | |
References | () https://bugs.launchpad.net/swift3/+bug/1497424 - | |
References | () https://github.com/openstack/swift3/blob/master/CHANGELOG - Patch | |
References | () https://swiftstack.com/docs/admin/release.html - |
Information
Published : 2016-01-13 15:59
Updated : 2024-11-21 02:38
NVD link : CVE-2015-8466
Mitre link : CVE-2015-8466
CVE.ORG link : CVE-2015-8466
JSON object : View
Products Affected
openstack
- swift3
fedoraproject
- fedora
CWE
CWE-20
Improper Input Validation