Swift OpenStack Swift

Do you want an email whenever new security vulnerabilities are reported in OpenStack Swift?

By the Year

In 2024 there have been 0 vulnerabilities in OpenStack Swift . Last year Swift had 1 security vulnerability published. Right now, Swift is on track to have less security vulnerabilities in 2024 than it did last year.

Year Vulnerabilities Average Score
2024 0 0.00
2023 1 6.50
2022 0 0.00
2021 1 4.30
2020 0 0.00
2019 0 0.00
2018 0 0.00

It may take a day or so for new Swift vulnerabilities to show up in the stats or in the list of recent security vulnerabilties. Additionally vulnerabilities may be tagged under a different product or component name.

Recent OpenStack Swift Security Vulnerabilities

An issue was discovered in OpenStack Swift before 2.28.1, 2.29.x before 2.29.2, and 2.30.0

CVE-2022-47950 6.5 - Medium - January 18, 2023

An issue was discovered in OpenStack Swift before 2.28.1, 2.29.x before 2.29.2, and 2.30.0. By supplying crafted XML files, an authenticated user may coerce the S3 API into returning arbitrary file contents from the host server, resulting in unauthorized read access to potentially sensitive data. This impacts both s3api deployments (Rocky or later), and swift3 deployments (Queens and earlier, no longer actively developed).

Files or Directories Accessible to External Parties

In OpenStack Swift through 2.10.1

CVE-2017-8761 4.3 - Medium - June 02, 2021

In OpenStack Swift through 2.10.1, 2.11.0 through 2.13.0, and 2.14.0, the proxy-server logs full tempurl paths, potentially leaking reusable tempurl signatures to anyone with read access to these logs. All Swift deployments using the tempurl middleware are affected.

Information Disclosure

OpenStack Object Storage (Swift) before 2.3.1 (Kilo), 2.4.x, and 2.5.x before 2.5.1 (Liberty) do not properly close server connections, which

CVE-2016-0738 7.5 - High - January 29, 2016

OpenStack Object Storage (Swift) before 2.3.1 (Kilo), 2.4.x, and 2.5.x before 2.5.1 (Liberty) do not properly close server connections, which allows remote attackers to cause a denial of service (proxy-server resource consumption) via a series of interrupted requests to a Large Object URL.

Resource Management Errors

OpenStack Object Storage (Swift) before 2.4.0 does not properly close client connections, which

CVE-2016-0737 7.5 - High - January 29, 2016

OpenStack Object Storage (Swift) before 2.4.0 does not properly close client connections, which allows remote attackers to cause a denial of service (proxy-server resource consumption) via a series of interrupted requests to a Large Object URL.

Resource Management Errors

Cross-site scripting (XSS) vulnerability in OpenStack Swift 1.11.0 through 1.13.1

CVE-2014-3497 - July 03, 2014

Cross-site scripting (XSS) vulnerability in OpenStack Swift 1.11.0 through 1.13.1 allows remote attackers to inject arbitrary web script or HTML via the WWW-Authenticate header.

XSS

OpenStack Object Storage (swift) before 1.7.0 uses the loads function in the pickle Python module unsafely when storing and loading metadata in memcached, which

CVE-2012-4406 9.8 - Critical - October 22, 2012

OpenStack Object Storage (swift) before 1.7.0 uses the loads function in the pickle Python module unsafely when storing and loading metadata in memcached, which allows remote attackers to execute arbitrary code via a crafted pickle object.

Marshaling, Unmarshaling

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Red Hat Gluster Storage Management Console or by OpenStack? Click the Watch button to subscribe.

OpenStack
Vendor

subscribe