Bug 1209994 (CVE-2015-1856)
| Summary: | CVE-2015-1856 OpenStack Swift: unauthorized deletion of versioned Swift object | ||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | Vasyl Kaigorodov <vkaigoro> | ||||||||
| Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> | ||||||||
| Status: | CLOSED ERRATA | QA Contact: | |||||||||
| Severity: | medium | Docs Contact: | |||||||||
| Priority: | medium | ||||||||||
| Version: | unspecified | CC: | abaron, aortega, apevec, ayoung, chrisw, dallan, derekh, gkotton, gmollett, lhh, lpeer, markmc, nlevinki, rbryant, rfortier, sclewis, security-response-team, sisharma, smohan, srevivo, ssaha, vbellur, zaitcev | ||||||||
| Target Milestone: | --- | Keywords: | Security | ||||||||
| Target Release: | --- | ||||||||||
| Hardware: | All | ||||||||||
| OS: | Linux | ||||||||||
| Whiteboard: | |||||||||||
| Fixed In Version: | Doc Type: | Bug Fix | |||||||||
| Doc Text: |
A flaw was found in OpenStack Object Storage that could allow an authenticated user to delete the most recent version of a versioned object regardless of ownership. To exploit this flaw, an attacker must know the name of the object and have listing access to the x-versions-location container.
|
Story Points: | --- | ||||||||
| Clone Of: | Environment: | ||||||||||
| Last Closed: | 2017-03-23 06:47:10 UTC | Type: | --- | ||||||||
| Regression: | --- | Mount Type: | --- | ||||||||
| Documentation: | --- | CRM: | |||||||||
| Verified Versions: | Category: | --- | |||||||||
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |||||||||
| Cloudforms Team: | --- | Target Upstream Version: | |||||||||
| Embargoed: | |||||||||||
| Bug Depends On: | 1246357, 1246358, 1246360, 1248348, 1248349 | ||||||||||
| Bug Blocks: | 1209996 | ||||||||||
| Attachments: |
|
||||||||||
|
Description
Vasyl Kaigorodov
2015-04-08 15:41:52 UTC
Created attachment 1013074 [details]
cve-2015-1856-master-kilo.patch
Created attachment 1013075 [details]
cve-2015-1856-stable-icehouse.patch
Created attachment 1013076 [details]
cve-2015-1856-stable-juno.patch
Created openstack-swift tracking bugs for this issue: Affects: fedora-all [bug 1246358] Affects: openstack-rdo [bug 1246360] This issue has been addressed in the following products: OpenStack 6 for RHEL 7 Via RHSA-2015:1681 https://rhn.redhat.com/errata/RHSA-2015-1681.html This issue has been addressed in the following products: OpenStack 5 for RHEL 6 OpenStack 5 for RHEL 7 Via RHSA-2015:1684 https://rhn.redhat.com/errata/RHSA-2015-1684.html This issue has been addressed in the following products: Red Hat Gluster Storage 3.1 for RHEL 6 Native Client for RHEL 6 for Red Hat Storage Via RHSA-2015:1845 https://rhn.redhat.com/errata/RHSA-2015-1845.html This issue has been addressed in the following products: Red Hat Gluster Storage 3.1 for RHEL 7 Native Client for RHEL 7 for Red Hat Storage Via RHSA-2015:1846 https://rhn.redhat.com/errata/RHSA-2015-1846.html |