ISOMAN

CVE

CVE-2015-1856

OpenStack Object Storage (Swift) before 2.3.0, when allow_version is configured, allows remote authenticated users to delete the latest version of an object by leveraging listing access to the x-versions-location container.

Severity
MEDIUM
CVSS
5.5
Published
Modified

Linked Releases

References

  1. http://lists.fedoraproject.org/pipermail/package-announce/2015-August/163113.html
  2. http://lists.openstack.org/pipermail/openstack-announce/2015-April/000349.html
  3. http://lists.opensuse.org/opensuse-security-announce/2015-10/msg00025.html
  4. http://rhn.redhat.com/errata/RHSA-2015-1681.html
  5. http://rhn.redhat.com/errata/RHSA-2015-1684.html
  6. http://rhn.redhat.com/errata/RHSA-2015-1845.html
  7. http://rhn.redhat.com/errata/RHSA-2015-1846.html
  8. http://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.html
  9. http://www.securityfocus.com/bid/74182
  10. http://www.ubuntu.com/usn/USN-2704-1
  11. https://bugs.launchpad.net/swift/+bug/1430645
  12. http://lists.fedoraproject.org/pipermail/package-announce/2015-August/163113.html
  13. http://lists.openstack.org/pipermail/openstack-announce/2015-April/000349.html
  14. http://lists.opensuse.org/opensuse-security-announce/2015-10/msg00025.html
  15. http://rhn.redhat.com/errata/RHSA-2015-1681.html
  16. http://rhn.redhat.com/errata/RHSA-2015-1684.html
  17. http://rhn.redhat.com/errata/RHSA-2015-1845.html
  18. http://rhn.redhat.com/errata/RHSA-2015-1846.html
  19. http://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.html
  20. http://www.securityfocus.com/bid/74182