CVE-2015-1856
published 2015-04-17CVE-2015-1856: OpenStack Object Storage (Swift) before 2.3.0, when allow_version is configured, allows remote authenticated users to delete the latest version of an object by…
PriorityP429medium5.5CVSS 2.0
AVNACLAuSCNIPAP
EPSS
3.95%
89.3th percentile
OpenStack Object Storage (Swift) before 2.3.0, when allow_version is configured, allows remote authenticated users to delete the latest version of an object by leveraging listing access to the x-versions-location container.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | swift | < swift 2.2.0-2 (bookworm) | swift 2.2.0-2 (bookworm) |
| openstack | swift | <= 2.2.2 | — |
| openstack | swift | >= 0 < 2.2.0-2 | 2.2.0-2 |
| openstack | swift | >= 0 < 2.2.0-2 | 2.2.0-2 |
| openstack | swift | >= 0 < 2.2.0-2 | 2.2.0-2 |
| openstack | swift | >= 0 < 2.2.0-2 | 2.2.0-2 |
| openstack | swift | >= 0 < 2.3.0 | 2.3.0 |
| openstack | swift | >= 0 < 1.13.1-0ubuntu1.2 | 1.13.1-0ubuntu1.2 |
CVSS provenance
nvdv2.05.5MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:P
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_ubuntu4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
OpenStack Swift Unauthorized delete of versioned Swift object
osv·2022-05-14
CVE-2015-1856 [MEDIUM] OpenStack Swift Unauthorized delete of versioned Swift object
OpenStack Swift Unauthorized delete of versioned Swift object
OpenStack Object Storage (Swift) before 2.3.0, when allow_version is configured, allows remote authenticated users to delete the latest version of an object by leveraging listing access to the x-versions-location container.
GHSA
OpenStack Swift Unauthorized delete of versioned Swift object
ghsa·2022-05-14
CVE-2015-1856 [MEDIUM] OpenStack Swift Unauthorized delete of versioned Swift object
OpenStack Swift Unauthorized delete of versioned Swift object
OpenStack Object Storage (Swift) before 2.3.0, when allow_version is configured, allows remote authenticated users to delete the latest version of an object by leveraging listing access to the x-versions-location container.
OSV
swift vulnerabilities
osv·2015-08-06·CVSS 4.0
CVE-2014-7960 [MEDIUM] swift vulnerabilities
swift vulnerabilities
Rajaneesh Singh discovered Swift does not properly enforce metadata
limits. An attacker could abuse this issue to store more metadata than
allowed by policy. (CVE-2014-7960)
Clay Gerrard discovered Swift allowed users to delete the latest version
of object regardless of object permissions when allow_version is
configured. An attacker could use this issue to delete objects.
(CVE-2015-1856)
OSV
CVE-2015-1856: OpenStack Object Storage (Swift) before 2
osv·2015-04-17·CVSS 5.5
CVE-2015-1856 [MEDIUM] CVE-2015-1856: OpenStack Object Storage (Swift) before 2
OpenStack Object Storage (Swift) before 2.3.0, when allow_version is configured, allows remote authenticated users to delete the latest version of an object by leveraging listing access to the x-versions-location container.
Ubuntu
Swift vulnerabilities
vendor_ubuntu·2015-08-06·CVSS 4.0
CVE-2014-7960 [MEDIUM] Swift vulnerabilities
Title: Swift vulnerabilities
Summary: Several security issues were fixed in Swift.
Rajaneesh Singh discovered Swift does not properly enforce metadata
limits. An attacker could abuse this issue to store more metadata than
allowed by policy. (CVE-2014-7960)
Clay Gerrard discovered Swift allowed users to delete the latest version
of object regardless of object permissions when allow_version is
configured. An attacker could use this issue to delete objects.
(CVE-2015-1856)
Instructions: After a standard system update you need to restart swift to make
all the necessary changes.
Red Hat
Swift: unauthorized deletion of versioned Swift object
vendor_redhat·2015-04-15·CVSS 5.5
CVE-2015-1856 [MEDIUM] Swift: unauthorized deletion of versioned Swift object
Swift: unauthorized deletion of versioned Swift object
OpenStack Object Storage (Swift) before 2.3.0, when allow_version is configured, allows remote authenticated users to delete the latest version of an object by leveraging listing access to the x-versions-location container.
A flaw was found in OpenStack Object Storage that could allow an authenticated user to delete the most recent version of a versioned object regardless of ownership. To exploit this flaw, an attacker must know the name of the object and have listing access to the x-versions-location container.
Package: openstack-swift (Red Hat OpenStack Platform 4) - Will not fix
Debian
CVE-2015-1856: swift - OpenStack Object Storage (Swift) before 2.3.0, when allow_version is configured,...
vendor_debian·2015·CVSS 5.5
CVE-2015-1856 [MEDIUM] CVE-2015-1856: swift - OpenStack Object Storage (Swift) before 2.3.0, when allow_version is configured,...
OpenStack Object Storage (Swift) before 2.3.0, when allow_version is configured, allows remote authenticated users to delete the latest version of an object by leveraging listing access to the x-versions-location container.
Scope: local
bookworm: resolved (fixed in 2.2.0-2)
bullseye: resolved (fixed in 2.2.0-2)
forky: resolved (fixed in 2.2.0-2)
sid: resolved (fixed in 2.2.0-2)
trixie: resolved (fixed in 2.2.0-2)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-1856 openstack-swift: OpenStack Swift: unauthorized deletion of versioned Swift object [fedora-all]
bugzilla·2015-07-24·CVSS 5.5
CVE-2015-1856 [MEDIUM] CVE-2015-1856 openstack-swift: OpenStack Swift: unauthorized deletion of versioned Swift object [fedora-all]
CVE-2015-1856 openstack-swift: OpenStack Swift: unauthorized deletion of versioned Swift object [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects
Bugzilla
CVE-2015-1856 OpenStack Swift: unauthorized deletion of versioned Swift object
bugzilla·2015-04-08·CVSS 5.5
CVE-2015-1856 [MEDIUM] CVE-2015-1856 OpenStack Swift: unauthorized deletion of versioned Swift object
CVE-2015-1856 OpenStack Swift: unauthorized deletion of versioned Swift object
Upstream reported the below vulnerability in OpenStack:
"""
Title: Unauthorized delete of versioned Swift object
Reporter: Clay Gerrard (SwiftStack)
Products: Swift
Affects: up to version 2.2.2
Description:
Clay Gerrard from SwiftStack reported a vulnerability in Swift object
versioning. An authenticated user can delete the most recent version of
any versioned object who's name is known if the user have listing access
to the x-versions-location container. Only Swift setups with
allow_version setting are affected.
"""
Acknowledgements:
Red Hat would like to thank the OpenStack project for reporting this issue. Upstream acknowledges Clay Gerrard of SwiftStack as the original reporter.
Discussion:
Created att
http://lists.fedoraproject.org/pipermail/package-announce/2015-August/163113.htmlhttp://lists.openstack.org/pipermail/openstack-announce/2015-April/000349.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-10/msg00025.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1681.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1684.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1845.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1846.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.htmlhttp://www.securityfocus.com/bid/74182http://www.ubuntu.com/usn/USN-2704-1https://bugs.launchpad.net/swift/+bug/1430645http://lists.fedoraproject.org/pipermail/package-announce/2015-August/163113.htmlhttp://lists.openstack.org/pipermail/openstack-announce/2015-April/000349.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-10/msg00025.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1681.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1684.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1845.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1846.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.htmlhttp://www.securityfocus.com/bid/74182http://www.ubuntu.com/usn/USN-2704-1https://bugs.launchpad.net/swift/+bug/1430645
2015-04-17
Published