CVE-2015-5242
published 2015-11-25CVE-2015-5242: OpenStack Swift-on-File (aka Swiftonfile) does not properly restrict use of the pickle Python module when loading metadata, which allows remote authenticated…
PriorityP433medium6CVSS 2.0
AVNACMAuSCPIPAP
EPSS
2.23%
80.8th percentile
OpenStack Swift-on-File (aka Swiftonfile) does not properly restrict use of the pickle Python module when loading metadata, which allows remote authenticated users to execute arbitrary code via a crafted extended attribute (xattrs).
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | gluster_storage | — | — |
CVSS provenance
nvdv2.06.0MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:P
vendor_redhat6.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
swiftonfile: use of insecure Python pickle for metadata serialization and storage
vendor_redhat·2015-10-20·CVSS 6.0
CVE-2015-5242 [MEDIUM] swiftonfile: use of insecure Python pickle for metadata serialization and storage
swiftonfile: use of insecure Python pickle for metadata serialization and storage
OpenStack Swift-on-File (aka Swiftonfile) does not properly restrict use of the pickle Python module when loading metadata, which allows remote authenticated users to execute arbitrary code via a crafted extended attribute (xattrs).
A flaw was found in the way swiftonfile (gluster-swift) serialized and stored metadata on disk by using Python's pickle module. A remote, authenticated user could use this flaw to execute arbitrary code on the storage node.
GHSA
GHSA-864h-cmr8-fpc7: OpenStack Swift-on-File (aka Swiftonfile) does not properly restrict use of the pickle Python module when loading metadata, which allows remote authen
ghsa_unreviewed·2022-05-17
CVE-2015-5242 [MEDIUM] CWE-94 GHSA-864h-cmr8-fpc7: OpenStack Swift-on-File (aka Swiftonfile) does not properly restrict use of the pickle Python module when loading metadata, which allows remote authen
OpenStack Swift-on-File (aka Swiftonfile) does not properly restrict use of the pickle Python module when loading metadata, which allows remote authenticated users to execute arbitrary code via a crafted extended attribute (xattrs).
No detection rules found.
No public exploits indexed.
http://rhn.redhat.com/errata/RHSA-2015-1918.htmlhttps://access.redhat.com/solutions/1985893https://bugzilla.redhat.com/show_bug.cgi?id=1258743https://review.openstack.org/#/c/237994/http://rhn.redhat.com/errata/RHSA-2015-1918.htmlhttps://access.redhat.com/solutions/1985893https://bugzilla.redhat.com/show_bug.cgi?id=1258743https://review.openstack.org/#/c/237994/
2015-11-25
Published