CVE-2014-3497: XSS
Published Jul 3, 2014
·Updated
Cross-site scripting (XSS) vulnerability in OpenStack Swift 1.11.0 through 1.13.1 allows remote attackers to inject arbitrary web script or HTML via the WWW-Authenticate header.
Affected Software
6 affected components
Openstack Swift=1.11.0
Openstack Swift=1.12.0
Openstack Swift=1.13.0
Openstack Swift=1.13.1
Openstack Swift=1.13.1-rc1
Openstack Swift=1.13.1-rc2
Event History
Jul 3, 2014
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-3497?
CVE-2014-3497 is classified as a moderate severity vulnerability due to its ability to allow XSS attacks.
2
How do I fix CVE-2014-3497?
To fix CVE-2014-3497, upgrade OpenStack Swift to version 1.13.2 or later.
3
What versions of OpenStack Swift are affected by CVE-2014-3497?
CVE-2014-3497 affects OpenStack Swift versions from 1.11.0 to 1.13.1, including release candidates.
4
What type of attack does CVE-2014-3497 allow?
CVE-2014-3497 allows remote attackers to inject arbitrary web scripts or HTML via the WWW-Authenticate header.
5
Is CVE-2014-3497 a critical vulnerability for my organization?
CVE-2014-3497 may be critical depending on your use case, especially if your application handles sensitive user data.