CVE-2014-3497
published 2014-07-03CVE-2014-3497: Cross-site scripting (XSS) vulnerability in OpenStack Swift 1.11.0 through 1.13.1 allows remote attackers to inject arbitrary web script or HTML via the…
PriorityP419medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
2.08%
79.5th percentile
Cross-site scripting (XSS) vulnerability in OpenStack Swift 1.11.0 through 1.13.1 allows remote attackers to inject arbitrary web script or HTML via the WWW-Authenticate header.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | swift | < swift 1.13.1-1 (bookworm) | swift 1.13.1-1 (bookworm) |
| openstack | swift | — | — |
| openstack | swift | — | — |
| openstack | swift | — | — |
| openstack | swift | — | — |
| openstack | swift | >= 0 < 1.13.1-1 | 1.13.1-1 |
| openstack | swift | >= 0 < 1.13.1-1 | 1.13.1-1 |
| openstack | swift | >= 0 < 1.13.1-1 | 1.13.1-1 |
| openstack | swift | >= 0 < 1.13.1-1 | 1.13.1-1 |
| openstack | swift | >= 1.11.0 < 2.0.0 | 2.0.0 |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Swift vulnerability
vendor_ubuntu·2014-06-25
CVE-2014-3497 Swift vulnerability
Title: Swift vulnerability
Summary: Swift did not properly perform input validation of certain HTTP headers.
John Dickinson discovered that Swift did not properly quote the
WWW-Authenticate header value. If a user were tricked into navigating to a
malicious Swift URL, an attacker could conduct cross-site scripting
attacks. With cross-site scripting vulnerabilities, if a user were tricked
into viewing server output during a crafted server request, a remote
attacker could exploit this to modify the contents, or steal confidential
data, within the same domain.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
openstack-swift: XSS in Swift requests through WWW-Authenticate header
vendor_redhat·2014-06-19·CVSS 4.3
CVE-2014-3497 [MEDIUM] CWE-79 openstack-swift: XSS in Swift requests through WWW-Authenticate header
openstack-swift: XSS in Swift requests through WWW-Authenticate header
Cross-site scripting (XSS) vulnerability in OpenStack Swift 1.11.0 through 1.13.1 allows remote attackers to inject arbitrary web script or HTML via the WWW-Authenticate header.
It was found that Swift did not escape all HTTP header values, allowing data to be injected into the responses sent from the Swift server. This could lead to cross-site scripting attacks (and possibly other impacts) if a user were tricked into clicking on a malicious URL.
Package: openstack-swift (Red Hat OpenStack Platform 3) - Not affected
Package: openstack-swift (Red Hat OpenStack Platform 4) - Not affected
Debian
CVE-2014-3497: swift - Cross-site scripting (XSS) vulnerability in OpenStack Swift 1.11.0 through 1.13....
vendor_debian·2014·CVSS 4.3
CVE-2014-3497 [MEDIUM] CVE-2014-3497: swift - Cross-site scripting (XSS) vulnerability in OpenStack Swift 1.11.0 through 1.13....
Cross-site scripting (XSS) vulnerability in OpenStack Swift 1.11.0 through 1.13.1 allows remote attackers to inject arbitrary web script or HTML via the WWW-Authenticate header.
Scope: local
bookworm: resolved (fixed in 1.13.1-1)
bullseye: resolved (fixed in 1.13.1-1)
forky: resolved (fixed in 1.13.1-1)
sid: resolved (fixed in 1.13.1-1)
trixie: resolved (fixed in 1.13.1-1)
GHSA
OpenStack Swift Cross-site Scriping vulnerability
ghsa·2022-05-17
CVE-2014-3497 [MEDIUM] CWE-79 OpenStack Swift Cross-site Scriping vulnerability
OpenStack Swift Cross-site Scriping vulnerability
Cross-site scripting (XSS) vulnerability in OpenStack Swift 1.11.0 through 1.13.1 allows remote attackers to inject arbitrary web script or HTML via the WWW-Authenticate header.
OSV
OpenStack Swift Cross-site Scriping vulnerability
osv·2022-05-17
CVE-2014-3497 [MEDIUM] OpenStack Swift Cross-site Scriping vulnerability
OpenStack Swift Cross-site Scriping vulnerability
Cross-site scripting (XSS) vulnerability in OpenStack Swift 1.11.0 through 1.13.1 allows remote attackers to inject arbitrary web script or HTML via the WWW-Authenticate header.
OSV
CVE-2014-3497: Cross-site scripting (XSS) vulnerability in OpenStack Swift 1
osv·2014-07-03·CVSS 4.3
CVE-2014-3497 [MEDIUM] CVE-2014-3497: Cross-site scripting (XSS) vulnerability in OpenStack Swift 1
Cross-site scripting (XSS) vulnerability in OpenStack Swift 1.11.0 through 1.13.1 allows remote attackers to inject arbitrary web script or HTML via the WWW-Authenticate header.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-3497 openstack-swift: XSS in Swift requests through WWW-Authenticate header [epel-6]
bugzilla·2014-06-26·CVSS 4.3
CVE-2014-3497 [MEDIUM] CVE-2014-3497 openstack-swift: XSS in Swift requests through WWW-Authenticate header [epel-6]
CVE-2014-3497 openstack-swift: XSS in Swift requests through WWW-Authenticate header [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
epel-6 tracki
Bugzilla
CVE-2014-3497 openstack-swift: XSS in Swift requests through WWW-Authenticate header
bugzilla·2014-06-18·CVSS 4.3
CVE-2014-3497 [MEDIUM] CVE-2014-3497 openstack-swift: XSS in Swift requests through WWW-Authenticate header
CVE-2014-3497 openstack-swift: XSS in Swift requests through WWW-Authenticate header
The OpenStack project reports:
Title: XSS in Swift requests through WWW-Authenticate header
Reporter: Globo.com Security Team
Products: Swift
Versions: 1.11.0 to 1.13.1
Description:
Globo.com Security Team reported a vulnerability in Swift's header value
escaping. By tricking a Swift user into clicking a malicious URL, a
remote attacker may inject data in Swift response while still appearing
to come from the Swift server, potentially leading to other client-side
vulnerabilities. All Swift setups are affected.
Discussion:
Acknowledgements:
Red Hat would like to thank the OpenStack project for reporting this issue. Upstream acknowledges the Globo.com Security Team as the original reporter.
---
This i
http://lists.openstack.org/pipermail/openstack-announce/2014-June/000243.htmlhttp://secunia.com/advisories/59532http://www.openwall.com/lists/oss-security/2014/06/19/10http://www.securityfocus.com/bid/68116http://www.ubuntu.com/usn/USN-2256-1https://review.openstack.org/#/c/101031/https://review.openstack.org/#/c/101032/http://lists.openstack.org/pipermail/openstack-announce/2014-June/000243.htmlhttp://secunia.com/advisories/59532http://www.openwall.com/lists/oss-security/2014/06/19/10http://www.securityfocus.com/bid/68116http://www.ubuntu.com/usn/USN-2256-1https://review.openstack.org/#/c/101031/https://review.openstack.org/#/c/101032/
2014-07-03
Published