Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2012-4406


OpenStack Object Storage (swift) before 1.7.0 uses the loads function in the pickle Python module unsafely when storing and loading metadata in memcached, which allows remote attackers to execute arbitrary code via a crafted pickle object.


Published

2012-10-22T23:55:06.743

Last Modified

2025-04-11T00:51:21.963

Status

Deferred

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

10.0

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-502

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application openstack swift < 1.7.0 Yes
Operating System fedoraproject fedora 16 Yes
Application redhat gluster_storage_management_console 2.0 Yes
Application redhat gluster_storage_server_for_on-premise 2.0 Yes
Application redhat storage 2.0 Yes
Application redhat storage_for_public_cloud 2.0 Yes
Operating System redhat enterprise_linux_server 5.0 Yes
Operating System redhat enterprise_linux_server 6.0 Yes

References