Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLThmeGMtcW02NS12cHhn

Temporary urls leaked via logging

In OpenStack Swift prior to 2.15.2, the proxy-server logs full tempurl paths, potentially leaking reusable tempurl signatures to anyone with read access to these logs. All Swift deployments using the tempurl middleware are affected.

Permalink: https://github.com/advisories/GHSA-8fxc-qm65-vpxg
JSON: https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLThmeGMtcW02NS12cHhn
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Low
Classification: General
Published: almost 3 years ago
Updated: about 1 year ago


Identifiers: GHSA-8fxc-qm65-vpxg, CVE-2017-8761
References: Blast Radius: 0.0

Affected Packages

pypi:swift
Dependent packages: 1
Dependent repositories: 53
Downloads: 1,756 last month
Affected Version Ranges: < 2.15.2
Fixed in: 2.15.2
All affected versions: 1.0.2
All unaffected versions: 2.15.2, 2.17.1, 2.19.1, 2.19.2, 2.20.0, 2.21.0, 2.21.1, 2.22.0, 2.23.0, 2.23.1, 2.23.2, 2.23.3, 2.24.0, 2.25.0, 2.25.1, 2.25.2, 2.26.0, 2.27.0, 2.28.0, 2.28.1, 2.29.0, 2.29.1, 2.29.2, 2.30.0, 2.30.1, 2.31.0, 2.31.1, 2.32.0, 2.33.0