CVE-2012-4406
published 2012-10-22CVE-2012-4406: OpenStack Object Storage (swift) before 1.7.0 uses the loads function in the pickle Python module unsafely when storing and loading metadata in memcached…
PriorityP355critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
6.52%
93.0th percentile
OpenStack Object Storage (swift) before 1.7.0 uses the loads function in the pickle Python module unsafely when storing and loading metadata in memcached, which allows remote attackers to execute arbitrary code via a crafted pickle object.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | swift | < swift 1.4.8-2 (bookworm) | swift 1.4.8-2 (bookworm) |
| fedoraproject | fedora | — | — |
| openstack | swift | < 1.7.0 | 1.7.0 |
| openstack | swift | >= 0 < 1.4.8-2 | 1.4.8-2 |
| openstack | swift | >= 0 < 1.4.8-2 | 1.4.8-2 |
| openstack | swift | >= 0 < 1.4.8-2 | 1.4.8-2 |
| openstack | swift | >= 0 < 1.4.8-2 | 1.4.8-2 |
| openstack | swift | >= 0 < 1.7.0 | 1.7.0 |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | gluster_storage_management_console | — | — |
| redhat | gluster_storage_server_for_on-premise | — | — |
| redhat | storage | — | — |
| redhat | storage_for_public_cloud | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
OpenStack Swift vulnerabilities
vendor_ubuntu·2013-06-20·CVSS 9.8
CVE-2012-4406 [CRITICAL] OpenStack Swift vulnerabilities
Title: OpenStack Swift vulnerabilities
Summary: Multiple security issues were fixed in OpenStack Swift.
Sebastian Krahmer discovered that Swift used the loads function in the
pickle Python module when it was configured to use memcached. A remote
attacker on the same network as memcached could exploit this to execute
arbitrary code. This update adds a new memcache_serialization_support
option to support secure json serialization. For details on this new
option, please see /usr/share/doc/swift-proxy/memcache.conf-sample. This
issue only affected Ubuntu 12.04 LTS. (CVE-2012-4406)
Alex Gaynor discovered that Swift did not safely generate XML. An
attacker could potentially craft an account name to generate arbitrary XML
responses to trigger vulnerabilties in software parsing Swift's XML.
(CV
Red Hat
Openstack-Swift: insecure use of python pickle()
vendor_redhat·2012-05-30·CVSS 9.8
CVE-2012-4406 [CRITICAL] CWE-502 Openstack-Swift: insecure use of python pickle()
Openstack-Swift: insecure use of python pickle()
OpenStack Object Storage (swift) before 1.7.0 uses the loads function in the pickle Python module unsafely when storing and loading metadata in memcached, which allows remote attackers to execute arbitrary code via a crafted pickle object.
Debian
CVE-2012-4406: swift - OpenStack Object Storage (swift) before 1.7.0 uses the loads function in the pic...
vendor_debian·2012·CVSS 9.8
CVE-2012-4406 [CRITICAL] CVE-2012-4406: swift - OpenStack Object Storage (swift) before 1.7.0 uses the loads function in the pic...
OpenStack Object Storage (swift) before 1.7.0 uses the loads function in the pickle Python module unsafely when storing and loading metadata in memcached, which allows remote attackers to execute arbitrary code via a crafted pickle object.
Scope: local
bookworm: resolved (fixed in 1.4.8-2)
bullseye: resolved (fixed in 1.4.8-2)
forky: resolved (fixed in 1.4.8-2)
sid: resolved (fixed in 1.4.8-2)
trixie: resolved (fixed in 1.4.8-2)
GHSA
OpenStack Object Storage (swift) Code Injection vulnerability
ghsa·2022-05-17
CVE-2012-4406 [CRITICAL] CWE-502 OpenStack Object Storage (swift) Code Injection vulnerability
OpenStack Object Storage (swift) Code Injection vulnerability
OpenStack Object Storage (swift) before 1.7.0 uses the loads function in the pickle Python module unsafely when storing and loading metadata in memcached, which allows remote attackers to execute arbitrary code via a crafted pickle object.
OSV
OpenStack Object Storage (swift) Code Injection vulnerability
osv·2022-05-17
CVE-2012-4406 [CRITICAL] OpenStack Object Storage (swift) Code Injection vulnerability
OpenStack Object Storage (swift) Code Injection vulnerability
OpenStack Object Storage (swift) before 1.7.0 uses the loads function in the pickle Python module unsafely when storing and loading metadata in memcached, which allows remote attackers to execute arbitrary code via a crafted pickle object.
OSV
CVE-2012-4406: OpenStack Object Storage (swift) before 1
osv·2012-10-22·CVSS 9.8
CVE-2012-4406 [CRITICAL] CVE-2012-4406: OpenStack Object Storage (swift) before 1
OpenStack Object Storage (swift) before 1.7.0 uses the loads function in the pickle Python module unsafely when storing and loading metadata in memcached, which allows remote attackers to execute arbitrary code via a crafted pickle object.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-4406 Openstack-Swift: insecure use of python pickle() [epel-6]
bugzilla·2012-09-12·CVSS 9.8
CVE-2012-4406 [CRITICAL] CVE-2012-4406 Openstack-Swift: insecure use of python pickle() [epel-6]
CVE-2012-4406 Openstack-Swift: insecure use of python pickle() [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bug
Bugzilla
CVE-2012-4406 Openstack-Swift: insecure use of python pickle() [fedora-all]
bugzilla·2012-09-05·CVSS 9.8
CVE-2012-4406 [CRITICAL] CVE-2012-4406 Openstack-Swift: insecure use of python pickle() [fedora-all]
CVE-2012-4406 Openstack-Swift: insecure use of python pickle() [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security
Bugzilla
CVE-2012-4406 Openstack-Swift: insecure use of python pickle()
bugzilla·2012-09-05·CVSS 9.8
CVE-2012-4406 [CRITICAL] CVE-2012-4406 Openstack-Swift: insecure use of python pickle()
CVE-2012-4406 Openstack-Swift: insecure use of python pickle()
Sebastian Krahmer ([email protected]) reports:
swift uses pickle to store and load meta data. pickle is insecure
and allows to execute arbitrary code in loads().
[...]
BTW, you can read more on executing code via pickle or cPickle here:
http://nadiana.com/python-pickle-insecure
https://bugs.launchpad.net/swift/+bug/1006414
Additionally:
==
Pickle is insecure in a model where an untrusted user can provide the pickled
data. In the Swift model the data is pickled by Swift itself and stored in
memcache, so the attack vector would suppose direct write access by an
untrusted user to memcached data ?
==
memcached on Swift runs on every proxy servers and shared a cache so it bind
on the internal network ip. For swift we always assu
http://lists.fedoraproject.org/pipermail/package-announce/2012-October/089472.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1379.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0691.htmlhttp://www.openwall.com/lists/oss-security/2012/09/05/16http://www.openwall.com/lists/oss-security/2012/09/05/4http://www.securityfocus.com/bid/55420https://bugs.launchpad.net/swift/+bug/1006414https://bugzilla.redhat.com/show_bug.cgi?id=854757https://exchange.xforce.ibmcloud.com/vulnerabilities/79140https://github.com/openstack/swift/commit/e1ff51c04554d51616d2845f92ab726cb0e5831ahttps://launchpad.net/swift/+milestone/1.7.0http://lists.fedoraproject.org/pipermail/package-announce/2012-October/089472.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1379.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0691.htmlhttp://www.openwall.com/lists/oss-security/2012/09/05/16http://www.openwall.com/lists/oss-security/2012/09/05/4http://www.securityfocus.com/bid/55420https://bugs.launchpad.net/swift/+bug/1006414https://bugzilla.redhat.com/show_bug.cgi?id=854757https://exchange.xforce.ibmcloud.com/vulnerabilities/79140https://github.com/openstack/swift/commit/e1ff51c04554d51616d2845f92ab726cb0e5831ahttps://launchpad.net/swift/+milestone/1.7.0
2012-10-22
Published