First published: Thu Jul 03 2014(Updated: )
Cross-site scripting (XSS) vulnerability in OpenStack Swift 1.11.0 through 1.13.1 allows remote attackers to inject arbitrary web script or HTML via the WWW-Authenticate header.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
OpenStack Swift3 | =1.11.0 | |
OpenStack Swift3 | =1.12.0 | |
OpenStack Swift3 | =1.13.0 | |
OpenStack Swift3 | =1.13.1 | |
OpenStack Swift3 | =1.13.1-rc1 | |
OpenStack Swift3 | =1.13.1-rc2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-3497 is classified as a moderate severity vulnerability due to its ability to allow XSS attacks.
To fix CVE-2014-3497, upgrade OpenStack Swift to version 1.13.2 or later.
CVE-2014-3497 affects OpenStack Swift versions from 1.11.0 to 1.13.1, including release candidates.
CVE-2014-3497 allows remote attackers to inject arbitrary web scripts or HTML via the WWW-Authenticate header.
CVE-2014-3497 may be critical depending on your use case, especially if your application handles sensitive user data.