CVE-2017-8761

In OpenStack Swift through 2.10.1, 2.11.0 through 2.13.0, and 2.14.0, the proxy-server logs full tempurl paths, potentially leaking reusable tempurl signatures to anyone with read access to these logs. All Swift deployments using the tempurl middleware are affected.
References
Link Resource
https://launchpad.net/bugs/1685798 Issue Tracking Third Party Advisory
https://launchpad.net/bugs/1685798 Issue Tracking Third Party Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:openstack:swift:*:*:*:*:*:*:*:*
cpe:2.3:a:openstack:swift:*:*:*:*:*:*:*:*
cpe:2.3:a:openstack:swift:2.14.0:*:*:*:*:*:*:*

History

21 Nov 2024, 03:34

Type Values Removed Values Added
References () https://launchpad.net/bugs/1685798 - Issue Tracking, Third Party Advisory () https://launchpad.net/bugs/1685798 - Issue Tracking, Third Party Advisory

Information

Published : 2021-06-02 14:15

Updated : 2024-11-21 03:34


NVD link : CVE-2017-8761

Mitre link : CVE-2017-8761

CVE.ORG link : CVE-2017-8761


JSON object : View

Products Affected

openstack

  • swift
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor