HIGH
Swift: TempURL timing attack
Published Jan 23, 2014
8.7
HIGHCVSS 4.0
EPSS 1.91%
Description
The TempURL middleware in OpenStack Object Storage (Swift) 1.4.6 through 1.8.0, 1.9.0 through 1.10.0, and 1.11.0 allows remote attackers to obtain secret URLs by leveraging an object name and a timing side-channel attack.
Affected products
No data.
OR
- 1.4.6
- 1.4.7
- 1.4.8
- 1.5.0
- 1.6.0
- 1.7.0
- 1.7.2
- 1.7.4
- 1.7.5
- 1.7.6
- 1.8.0
- 1.9.0
- 1.9.1
- 1.9.2
- 1.10.0
- 1.11.0
No data.
OpenStack 3 for RHEL 6
openstack-swift-0:1.8.0-8.el6ost
Fixed · RHSA-2014:0367
OpenStack 4 for RHEL 6
openstack-swift-0:1.10.0-3.el6ost
Fixed · RHSA-2014:0232
| Product | Package | State | Advisory |
|---|---|---|---|
| OpenStack 3 for RHEL 6 | openstack-swift-0:1.8.0-8.el6ost | Fixed | RHSA-2014:0367 |
| OpenStack 4 for RHEL 6 | openstack-swift-0:1.10.0-3.el6ost | Fixed | RHSA-2014:0232 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (10)
- http://rhn.redhat.com/errata/RHSA-2014-0232.html vendor-advisoryx_refsource_REDHAT
- http://www.openwall.com/lists/oss-security/2014/01/17/5 mailing-listx_refsource_MLISTPatch
- https://access.redhat.com/security/cve/CVE-2014-0006 Vendor Advisory
- https://bugs.launchpad.net/swift/+bug/1265665 x_refsource_CONFIRMVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1051670 Issue Tracking
- https://github.com/advisories/GHSA-cf9m-q836-vf26 Advisory
- https://github.com/openstack/swift/commit/754633988931e4095530f6b13389c254096eb485
- https://github.com/pypa/advisory-database/tree/main/vulns/swift/PYSEC-2014-116.yaml
- https://nvd.nist.gov/vuln/detail/CVE-2014-0006
- https://www.cve.org/CVERecord?id=CVE-2014-0006
| Link | Providers | Tags |
|---|---|---|
| http://rhn.redhat.com/errata/RHSA-2014-0232.html | vendor-advisoryx_refsource_REDHAT | |
| http://www.openwall.com/lists/oss-security/2014/01/17/5 | mailing-listx_refsource_MLISTPatch | |
| https://access.redhat.com/security/cve/CVE-2014-0006 | Vendor Advisory | |
| https://bugs.launchpad.net/swift/+bug/1265665 | x_refsource_CONFIRMVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1051670 | Issue Tracking | |
| https://github.com/advisories/GHSA-cf9m-q836-vf26 | Advisory | |
| https://github.com/openstack/swift/commit/754633988931e4095530f6b13389c254096eb485 | ||
| https://github.com/pypa/advisory-database/tree/main/vulns/swift/PYSEC-2014-116.yaml | ||
| https://nvd.nist.gov/vuln/detail/CVE-2014-0006 | ||
| https://www.cve.org/CVERecord?id=CVE-2014-0006 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jan 23, 2014
Updated Aug 6, 2024
Reserved Dec 3, 2013
Link CVE-2014-0006
CISA Vulnrichment
GHSA-CF9M-Q836-VF26 Updated n/a