Lucene search

K

Swift Security Vulnerabilities

cve
cve

CVE-2012-4406

OpenStack Object Storage (swift) before 1.7.0 uses the loads function in the pickle Python module unsafely when storing and loading metadata in memcached, which allows remote attackers to execute arbitrary code via a crafted pickle object.

9.8CVSS

9.4AI Score

0.05EPSS

2012-10-22 11:55 PM
48
cve
cve

CVE-2013-4155

OpenStack Swift before 1.9.1 in Folsom, Grizzly, and Havana allows authenticated users to cause a denial of service ("superfluous" tombstone consumption and Swift cluster slowdown) via a DELETE request with a timestamp that is older than expected.

6AI Score

0.003EPSS

2013-08-20 10:55 PM
34
cve
cve

CVE-2013-6396

The OpenStack Python client library for Swift (python-swiftclient) 1.0 through 1.9.0 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

5.8AI Score

0.001EPSS

2014-02-18 07:55 PM
26
2
cve
cve

CVE-2014-0006

The TempURL middleware in OpenStack Object Storage (Swift) 1.4.6 through 1.8.0, 1.9.0 through 1.10.0, and 1.11.0 allows remote attackers to obtain secret URLs by leveraging an object name and a timing side-channel attack.

6.3AI Score

0.003EPSS

2014-01-23 01:55 AM
35
cve
cve

CVE-2014-3497

Cross-site scripting (XSS) vulnerability in OpenStack Swift 1.11.0 through 1.13.1 allows remote attackers to inject arbitrary web script or HTML via the WWW-Authenticate header.

5.5AI Score

0.003EPSS

2014-07-03 05:55 PM
38
cve
cve

CVE-2014-7960

OpenStack Object Storage (Swift) before 2.2.0 allows remote authenticated users to bypass the max_meta_count and other metadata constraints via multiple crafted requests which exceed the limit when combined.

6.1AI Score

0.002EPSS

2014-10-17 03:55 PM
24
cve
cve

CVE-2015-1856

OpenStack Object Storage (Swift) before 2.3.0, when allow_version is configured, allows remote authenticated users to delete the latest version of an object by leveraging listing access to the x-versions-location container.

6AI Score

0.004EPSS

2015-04-17 05:59 PM
32
cve
cve

CVE-2015-5223

OpenStack Object Storage (Swift) before 2.4.0 allows attackers to obtain sensitive information via a PUT tempurl and a DLO object manifest that references an object in another container.

7AI Score

0.007EPSS

2015-10-26 05:59 PM
30
cve
cve

CVE-2016-0737

OpenStack Object Storage (Swift) before 2.4.0 does not properly close client connections, which allows remote attackers to cause a denial of service (proxy-server resource consumption) via a series of interrupted requests to a Large Object URL.

7.5CVSS

7.1AI Score

0.047EPSS

2016-01-29 08:59 PM
43
cve
cve

CVE-2016-0738

OpenStack Object Storage (Swift) before 2.3.1 (Kilo), 2.4.x, and 2.5.x before 2.5.1 (Liberty) do not properly close server connections, which allows remote attackers to cause a denial of service (proxy-server resource consumption) via a series of interrupted requests to a Large Object URL.

7.5CVSS

7.1AI Score

0.047EPSS

2016-01-29 08:59 PM
44
cve
cve

CVE-2017-16613

An issue was discovered in middleware.py in OpenStack Swauth through 1.2.0 when used with OpenStack Swift through 2.15.1. The Swift object store and proxy server are saving (unhashed) tokens retrieved from the Swauth middleware authentication mechanism to a log file as part of a GET URI. This allow...

9.8CVSS

9.3AI Score

0.004EPSS

2017-11-21 01:29 PM
34
cve
cve

CVE-2017-8761

In OpenStack Swift through 2.10.1, 2.11.0 through 2.13.0, and 2.14.0, the proxy-server logs full tempurl paths, potentially leaking reusable tempurl signatures to anyone with read access to these logs. All Swift deployments using the tempurl middleware are affected.

4.3CVSS

4.3AI Score

0.001EPSS

2021-06-02 02:15 PM
52
cve
cve

CVE-2018-4220

An issue was discovered in certain Apple products. Swift before 4.1.1 Security Update 2018-001 is affected. The issue involves the "Swift for Ubuntu" component. It allows attackers to execute arbitrary code in a privileged context because write and execute permissions are enabled during library loa...

8.8CVSS

8.2AI Score

0.003EPSS

2018-06-08 06:29 PM
24
cve
cve

CVE-2019-8790

This issue was addresses by updating incorrect URLSession file descriptors management logic to match Swift 5.0. This issue is fixed in Swift 5.1.1 for Ubuntu. Incorrect management of file descriptors in URLSession could lead to inadvertent data disclosure.

5.5CVSS

5AI Score

0.0004EPSS

2020-10-27 08:15 PM
27
cve
cve

CVE-2020-9861

A stack overflow issue existed in Swift for Linux. The issue was addressed with improved input validation for dealing with deeply nested malicious JSON input.

7.5CVSS

7.2AI Score

0.001EPSS

2020-11-02 11:15 PM
26
cve
cve

CVE-2022-1642

A program using swift-corelibs-foundation is vulnerable to a denial of service attack caused by a potentially malicious source producing a JSON document containing a type mismatch. This vulnerability is caused by the interaction between a deserialization mechanism offered by the Swift standard libr...

7.5CVSS

7.5AI Score

0.001EPSS

2022-06-16 05:15 PM
49
3
cve
cve

CVE-2022-32389

Isode SWIFT v4.0.2 was discovered to contain hard-coded credentials in the Registry Editor. This allows attackers to access sensitive information such as user credentials and certificates.

7.5CVSS

7.4AI Score

0.001EPSS

2022-07-14 09:15 PM
42
5
cve
cve

CVE-2022-47950

An issue was discovered in OpenStack Swift before 2.28.1, 2.29.x before 2.29.2, and 2.30.0. By supplying crafted XML files, an authenticated user may coerce the S3 API into returning arbitrary file contents from the host server, resulting in unauthorized read access to potentially sensitive data. T...

6.5CVSS

5.9AI Score

0.001EPSS

2023-01-18 05:15 PM
57
cve
cve

CVE-2023-26154

Versions of the package pubnub before 7.4.0; all versions of the package com.pubnub:pubnub; versions of the package pubnub before 6.19.0; all versions of the package github.com/pubnub/go; versions of the package github.com/pubnub/go/v7 before 7.2.0; versions of the package pubnub before 7.3.0; vers...

5.9CVSS

5.6AI Score

0.001EPSS

2023-12-06 05:15 AM
30
cve
cve

CVE-2023-6289

The Swift Performance Lite WordPress plugin before 2.3.6.15 does not prevent users from exporting the plugin's settings, which may include sensitive information such as Cloudflare API tokens.

4.3CVSS

4.8AI Score

0.0004EPSS

2023-12-18 08:15 PM
20