cbcvebase.
CVE-2015-1856
published 2015-04-17

CVE-2015-1856: OpenStack Object Storage (Swift) before 2.3.0, when allow_version is configured, allows remote authenticated users to delete the latest version of an object by…

PriorityP429medium5.5CVSS 2.0
AVNACLAuSCNIPAP
EPSS
3.95%
89.3th percentile
OpenStack Object Storage (Swift) before 2.3.0, when allow_version is configured, allows remote authenticated users to delete the latest version of an object by leveraging listing access to the x-versions-location container.

Affected

11 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debianswift< swift 2.2.0-2 (bookworm)swift 2.2.0-2 (bookworm)
openstackswift<= 2.2.2
openstackswift>= 0 < 2.2.0-22.2.0-2
openstackswift>= 0 < 2.2.0-22.2.0-2
openstackswift>= 0 < 2.2.0-22.2.0-2
openstackswift>= 0 < 2.2.0-22.2.0-2
openstackswift>= 0 < 2.3.02.3.0
openstackswift>= 0 < 1.13.1-0ubuntu1.21.13.1-0ubuntu1.2

CVSS provenance

nvdv2.05.5MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:P
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_ubuntu4.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.