In OpenStack Swift through 2.10.1, 2.11.0 through 2.13.0, and 2.14.0, the proxy-server logs full tempurl paths, potentially leaking reusable tempurl signatures to anyone with read access to these logs. All Swift deployments using the tempurl middleware are affected.
2021-06-02T14:15:07.753
2024-11-21T03:34:38.637
Modified
CVSSv3.1: 4.3 (MEDIUM)
AV:N/AC:L/Au:S/C:P/I:N/A:N
8.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | openstack | swift | ≤ 2.10.1 | Yes |
Application | openstack | swift | ≤ 2.13.0 | Yes |
Application | openstack | swift | 2.14.0 | Yes |