============================================================ OSSA-2015-006: Unauthorized delete of versioned Swift object ============================================================ :Date: April 14, 2015 :CVE: CVE-2015-1856 Affects ~~~~~~~ - Swift: versions through 2.2.2 Description ~~~~~~~~~~~ Clay Gerrard from SwiftStack reported a vulnerability in Swift object versioning. An authenticated user can delete the most recent version of any versioned object whose name is known if the user have listing access to the x-versions-location container. Only Swift setups with allow_version setting are affected. Patches ~~~~~~~ - https://review.openstack.org/173366 (Icehouse) - https://review.openstack.org/173363 (Juno) - https://review.openstack.org/173361 (Kilo) Credits ~~~~~~~ - Clay Gerrard from SwiftStack (CVE-2015-1856) References ~~~~~~~~~~ - https://launchpad.net/bugs/1430645 - http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1856 Notes ~~~~~ - This fix will be included in the upcoming 2.3.0 release. -- Tristan Cacqueray OpenStack Vulnerability Management Team -------------- next part -------------- A non-text attachment was scrubbed... Name: signature.asc Type: application/pgp-signature Size: 473 bytes Desc: OpenPGP digital signature URL: <http://lists.openstack.org/pipermail/openstack-announce/attachments/20150414/1e08c47e/attachment.pgp>