CVE-2017-8761

In OpenStack Swift through 2.10.1, 2.11.0 through 2.13.0, and 2.14.0, the proxy-server logs full tempurl paths, potentially leaking reusable tempurl signatures to anyone with read access to these logs. All Swift deployments using the tempurl middleware are affected.
References
Link Resource
https://launchpad.net/bugs/1685798 Issue Tracking Third Party Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:openstack:swift:*:*:*:*:*:*:*:*
cpe:2.3:a:openstack:swift:*:*:*:*:*:*:*:*
cpe:2.3:a:openstack:swift:2.14.0:*:*:*:*:*:*:*

History

11 Jun 2021, 17:33

Type Values Removed Values Added
References (MISC) https://launchpad.net/bugs/1685798 - (MISC) https://launchpad.net/bugs/1685798 - Issue Tracking, Third Party Advisory
CVSS v2 : unknown
v3 : unknown
v2 : 4.0
v3 : 4.3
CPE cpe:2.3:a:openstack:swift:2.14.0:*:*:*:*:*:*:*
cpe:2.3:a:openstack:swift:*:*:*:*:*:*:*:*
CWE CWE-200

02 Jun 2021, 15:17

Type Values Removed Values Added
New CVE

Information

Published : 2021-06-02 14:15

Updated : 2023-12-10 13:55


NVD link : CVE-2017-8761

Mitre link : CVE-2017-8761

CVE.ORG link : CVE-2017-8761


JSON object : View

Products Affected

openstack

  • swift
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor