CVE-2015-8466: Input Validation
Published Jan 13, 2016
·Updated
Swift3 before 1.9 allows remote attackers to conduct replay attacks via an Authorization request that lacks a Date header.
Affected Software
2 affected components
Fedoraproject Fedora=23
Openstack Swift3<=1.8
Remediation
Patch Available
Event History
Jan 13, 2016
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-8466?
CVE-2015-8466 is classified as a medium severity vulnerability due to its potential for allowing replay attacks.
2
How do I fix CVE-2015-8466?
To fix CVE-2015-8466, upgrade to Swift3 version 1.9 or later which includes the necessary security patches.
3
Which software versions are affected by CVE-2015-8466?
CVE-2015-8466 affects OpenStack Swift3 versions up to and including 1.8 and Fedora version 23.
4
What type of attack does CVE-2015-8466 facilitate?
CVE-2015-8466 allows attackers to conduct replay attacks by exploiting the absence of a Date header in authorization requests.
5
What should I be aware of regarding CVE-2015-8466?
Organizations using affected versions should be vigilant about replay attacks and promptly update their software to mitigate the risk.