CVE-2015-5223: Infoleak
Published Oct 26, 2015
·Updated
OpenStack Object Storage (Swift) before 2.4.0 allows attackers to obtain sensitive information via a PUT tempurl and a DLO object manifest that references an object in another container.
Affected Software
2 affected componentsFixes available
pip/swift<2.4.0
2.4.0
Openstack Swift<=2.3.0
Event History
Oct 26, 2015
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
May 14, 2022
Advisory Published
03:59 AM
Frequently Asked Questions
1
What is the severity of CVE-2015-5223?
CVE-2015-5223 is classified as a medium severity vulnerability.
2
How do I fix CVE-2015-5223?
To fix CVE-2015-5223, upgrade OpenStack Object Storage (Swift) to version 2.4.0 or later.
3
What types of systems are affected by CVE-2015-5223?
CVE-2015-5223 affects OpenStack Object Storage (Swift) versions prior to 2.4.0.
4
What is the impact of exploiting CVE-2015-5223?
Exploiting CVE-2015-5223 allows attackers to obtain sensitive information from different containers.
5
Is there a workaround for CVE-2015-5223?
There is no official workaround; upgrading to the fixed version is recommended to mitigate CVE-2015-5223.