First published: Wed Jun 02 2021(Updated: )
In OpenStack Swift through 2.10.1, 2.11.0 through 2.13.0, and 2.14.0, the proxy-server logs full tempurl paths, potentially leaking reusable tempurl signatures to anyone with read access to these logs. All Swift deployments using the tempurl middleware are affected.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OpenStack Swift | <=2.10.1 | |
OpenStack Swift | >=2.11.0<=2.13.0 | |
OpenStack Swift | =2.14.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-8761 is a vulnerability in OpenStack Swift that can potentially leak reusable tempurl signatures to anyone with read access to the logs.
CVE-2017-8761 has a severity score of 4.3, which is considered medium.
CVE-2017-8761 affects OpenStack Swift versions 2.10.1 through 2.13.0 and 2.14.0.
The CVE-2017-8761 vulnerability can be exploited by reading the logs that contain the full tempurl paths.
Yes, a fix for CVE-2017-8761 is available. It is recommended to update to a version of OpenStack Swift that is not affected by the vulnerability.