Back

MEDIUM

openstack-swift: logs valid temporary urls which could result in access to data by anyone with access to the logfiles

Published Jun 2, 2021

Description

In OpenStack Swift through 2.10.1, 2.11.0 through 2.13.0, and 2.14.0, the proxy-server logs full tempurl paths, potentially leaking reusable tempurl signatures to anyone with read access to these logs. All Swift deployments using the tempurl middleware are affected.

Affected products

Remediation

Red Hat statement

Openstack Swift is no longer supported with the recent release of Red Hat Gluster Storage 3.5, hence openstack-swift will not be updated for this flaw.

Metrics

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jun 2, 2021
Updated Aug 5, 2024
Reserved May 3, 2017
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date May 27, 2020
GHSA-8FXC-QM65-VPXG