First published: Wed Jan 13 2016(Updated: )
Swift3 before 1.9 allows remote attackers to conduct replay attacks via an Authorization request that lacks a Date header.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Fedora | =23 | |
OpenStack Swift3 | <=1.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-8466 is classified as a medium severity vulnerability due to its potential for allowing replay attacks.
To fix CVE-2015-8466, upgrade to Swift3 version 1.9 or later which includes the necessary security patches.
CVE-2015-8466 affects OpenStack Swift3 versions up to and including 1.8 and Fedora version 23.
CVE-2015-8466 allows attackers to conduct replay attacks by exploiting the absence of a Date header in authorization requests.
Organizations using affected versions should be vigilant about replay attacks and promptly update their software to mitigate the risk.