SUSE-SU-2015:1846-1
Dashboard / Vulnerabilities / SUSE-SU-2015:1846-1
SUSE-SU-2015:1846-1
Summary: Security update for openstack-swift
Details: openstack-swift was updated to fix three security issues. These security issues were fixed: - CVE-2015-1856: OpenStack Object Storage (Swift), when allow_version is configured, allowed remote authenticated users to delete the latest version of an object by leveraging listing access to the x-versions-location container (bsc#927793). - CVE-2014-7960: OpenStack Object Storage (Swift) allowed remote authenticated users to bypass the max_meta_count and other metadata constraints via multiple crafted requests which exceed the limit when combined (bsc#900253). - CVE-2015-5223: Information leak via Swift tempurls (bsc#942641).
References: https://www.suse.com/support/update/announcement/2015/suse-su-20151846-1/, https://bugzilla.suse.com/900253, https://bugzilla.suse.com/927793, https://bugzilla.suse.com/942641, https://www.suse.com/security/cve/CVE-2014-7960, https://www.suse.com/security/cve/CVE-2015-1856, https://www.suse.com/security/cve/CVE-2015-5223
Affected packages
Package
Name: openstack-swift
Purl: pkg:rpm/suse/openstack-swift&distro=SUSE%20OpenStack%20Cloud%205
Affected ranges
Type: ECOSYSTEM
Events:
