Search CVE reports


Toggle filters

11 – 20 of 24 results


CVE-2016-9590

Low priority

Some fixes available 1 of 4

puppet-swift before versions 8.2.1, 9.4.4 is vulnerable to an information-disclosure in Red Hat OpenStack Platform director's installation of Object Storage (swift). During installation, the Puppet script responsible for deploying...

1 affected package

puppet-module-swift

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
puppet-module-swift Not affected Not affected Not affected Not affected Fixed
Show less packages

CVE-2016-10074

Medium priority

Some fixes available 14 of 19

The mail transport (aka Swift_Transport_MailTransport) in Swift Mailer before 5.4.5 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \" (backslash double...

1 affected package

libphp-swiftmailer

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libphp-swiftmailer Needs evaluation Fixed Fixed Fixed Fixed
Show less packages

CVE-2016-0738

Low priority

Some fixes available 1 of 4

OpenStack Object Storage (Swift) before 2.3.1 (Kilo), 2.4.x, and 2.5.x before 2.5.1 (Liberty) do not properly close server connections, which allows remote attackers to cause a denial of service (proxy-server resource consumption)...

1 affected package

swift

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
swift
Show less packages

CVE-2016-0737

Medium priority

Some fixes available 1 of 3

OpenStack Object Storage (Swift) before 2.4.0 does not properly close client connections, which allows remote attackers to cause a denial of service (proxy-server resource consumption) via a series of interrupted requests to a...

1 affected package

swift

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
swift
Show less packages

CVE-2015-8466

Medium priority

Some fixes available 1 of 4

Swift3 before 1.9 allows remote attackers to conduct replay attacks via an Authorization request that lacks a Date header.

1 affected package

swift-plugin-s3

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
swift-plugin-s3 Not in release Not in release Not in release Not in release Not affected
Show less packages

CVE-2015-5223

Medium priority

Some fixes available 1 of 3

OpenStack Object Storage (Swift) before 2.4.0 allows attackers to obtain sensitive information via a PUT tempurl and a DLO object manifest that references an object in another container.

1 affected package

swift

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
swift
Show less packages

CVE-2015-1856

Medium priority

Some fixes available 2 of 3

OpenStack Object Storage (Swift) before 2.3.0, when allow_version is configured, allows remote authenticated users to delete the latest version of an object by leveraging listing access to the x-versions-location container.

1 affected package

swift

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
swift
Show less packages

CVE-2014-7960

Low priority
Fixed

OpenStack Object Storage (Swift) before 2.2.0 allows remote authenticated users to bypass the max_meta_count and other metadata constraints via multiple crafted requests which exceed the limit when combined.

1 affected package

swift

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
swift
Show less packages

CVE-2014-3497

Medium priority
Fixed

Cross-site scripting (XSS) vulnerability in OpenStack Swift 1.11.0 through 1.13.1 allows remote attackers to inject arbitrary web script or HTML via the WWW-Authenticate header.

1 affected package

swift

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
swift
Show less packages

CVE-2013-6396

Low priority
Ignored

The OpenStack Python client library for Swift (python-swiftclient) 1.0 through 1.9.0 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information...

1 affected package

python-swiftclient

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-swiftclient
Show less packages