CVE-2015-5271: Infoleak
A flaw was discovered in the pipeline ordering of the swift staticweb middleware in the swiftproxy config generated from the openstack-tripleo-heat-templates. The staticweb middleware was incorrectly configured before keystone and under some conditions may allow unauthenticated access to private data.
Acknowledgements:
This issue was discovered by Christian Schwede and Emilien Macchi of Red Hat.
Other sources
The TripleO Heat templates (tripleo-heat-templates) do not properly order the Identity Service (keystone) before the OpenStack Object Storage (Swift) staticweb middleware in the swiftproxy pipeline when the staticweb middleware is enabled, which might allow remote attackers to obtain sensitive information from private containers via unspecified vectors.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-5271?
CVE-2015-5271 has a medium severity level due to potential information exposure to remote attackers.
How do I fix CVE-2015-5271?
To fix CVE-2015-5271, upgrade the tripleo-heat-templates package to version 0.8.7 or higher.
What software is affected by CVE-2015-5271?
CVE-2015-5271 affects Red Hat OpenStack 7.0 and OpenStack Tripleo Heat Templates.
What is the impact of CVE-2015-5271?
The impact of CVE-2015-5271 may allow remote attackers to obtain sensitive information due to improper middleware ordering.
Is there a known workaround for CVE-2015-5271?
There is no specific workaround documented for CVE-2015-5271; the recommended action is to apply the available patch.