CVE-2015-5271
published 2016-04-15CVE-2015-5271: The TripleO Heat templates (tripleo-heat-templates) do not properly order the Identity Service (keystone) before the OpenStack Object Storage (Swift) staticweb…
PriorityP339high7.5CVSS 3.0
AVNACLPRNUINSUCHINAN
EPSS
2.42%
82.2th percentile
The TripleO Heat templates (tripleo-heat-templates) do not properly order the Identity Service (keystone) before the OpenStack Object Storage (Swift) staticweb middleware in the swiftproxy pipeline when the staticweb middleware is enabled, which might allow remote attackers to obtain sensitive information from private containers via unspecified vectors.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | openstack | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
TripleO Heat templates might allow remote attackers to obtain sensitive information from private containers
osv·2022-05-17
CVE-2015-5271 [HIGH] TripleO Heat templates might allow remote attackers to obtain sensitive information from private containers
TripleO Heat templates might allow remote attackers to obtain sensitive information from private containers
The TripleO Heat templates (tripleo-heat-templates) do not properly order the Identity Service (keystone) before the OpenStack Object Storage (Swift) staticweb middleware in the swiftproxy pipeline when the staticweb middleware is enabled, which might allow remote attackers to obtain sensitive information from private containers via unspecified vectors.
GHSA
TripleO Heat templates might allow remote attackers to obtain sensitive information from private containers
ghsa·2022-05-17
CVE-2015-5271 [HIGH] CWE-200 TripleO Heat templates might allow remote attackers to obtain sensitive information from private containers
TripleO Heat templates might allow remote attackers to obtain sensitive information from private containers
The TripleO Heat templates (tripleo-heat-templates) do not properly order the Identity Service (keystone) before the OpenStack Object Storage (Swift) staticweb middleware in the swiftproxy pipeline when the staticweb middleware is enabled, which might allow remote attackers to obtain sensitive information from private containers via unspecified vectors.
OSV
CVE-2015-5271: The TripleO Heat templates (tripleo-heat-templates) do not properly order the Identity Service (keystone) before the OpenStack Object Storage (Swift)
osv·2016-04-15
CVE-2015-5271 CVE-2015-5271: The TripleO Heat templates (tripleo-heat-templates) do not properly order the Identity Service (keystone) before the OpenStack Object Storage (Swift)
The TripleO Heat templates (tripleo-heat-templates) do not properly order the Identity Service (keystone) before the OpenStack Object Storage (Swift) staticweb middleware in the swiftproxy pipeline when the staticweb middleware is enabled, which might allow remote attackers to obtain sensitive information from private containers via unspecified vectors.
Red Hat
openstack-tripleo-heat-templates: unsafe pipeline ordering of swift staticweb middleware
vendor_redhat·2015-09-22·CVSS 7.5
CVE-2015-5271 [HIGH] CWE-285 openstack-tripleo-heat-templates: unsafe pipeline ordering of swift staticweb middleware
openstack-tripleo-heat-templates: unsafe pipeline ordering of swift staticweb middleware
The TripleO Heat templates (tripleo-heat-templates) do not properly order the Identity Service (keystone) before the OpenStack Object Storage (Swift) staticweb middleware in the swiftproxy pipeline when the staticweb middleware is enabled, which might allow remote attackers to obtain sensitive information from private containers via unspecified vectors.
A flaw was discovered in the pipeline ordering of OpenStack Object Storage's staticweb middleware in the swiftproxy configuration generated from the openstack-tripleo-heat-templates package (OpenStack director). The staticweb middleware was incorrectly configured before the Identity Service, and under some conditions an attacker could use this flaw to
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-5271 openstack-tripleo-heat-templates: unsafe pipeline ordering of swift staticweb middleware [fedora-all]
bugzilla·2015-10-19·CVSS 7.5
CVE-2015-5271 [HIGH] CVE-2015-5271 openstack-tripleo-heat-templates: unsafe pipeline ordering of swift staticweb middleware [fedora-all]
CVE-2015-5271 openstack-tripleo-heat-templates: unsafe pipeline ordering of swift staticweb middleware [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue a
Bugzilla
CVE-2015-5271 openstack-tripleo-heat-templates: unsafe pipeline ordering of swift staticweb middleware
bugzilla·2015-09-10·CVSS 7.5
CVE-2015-5271 [HIGH] CVE-2015-5271 openstack-tripleo-heat-templates: unsafe pipeline ordering of swift staticweb middleware
CVE-2015-5271 openstack-tripleo-heat-templates: unsafe pipeline ordering of swift staticweb middleware
A flaw was discovered in the pipeline ordering of the swift staticweb middleware in the swiftproxy config generated from the openstack-tripleo-heat-templates. The staticweb middleware was incorrectly configured before keystone and under some conditions may allow unauthenticated access to private data.
Acknowledgements:
This issue was discovered by Christian Schwede and Emilien Macchi of Red Hat.
Discussion:
*** Bug 1261499 has been marked as a duplicate of this bug. ***
---
This issue has been addressed in the following products:
OpenStack 7.0 Director/Manager for RHEL 7
Via RHSA-2015:1862 https://access.redhat.com/errata/RHSA-2015:1862
---
Created openstack-tripleo-heat-templ
https://access.redhat.com/errata/RHSA-2015:1862https://bugs.launchpad.net/tripleo/+bug/1494896https://bugzilla.redhat.com/show_bug.cgi?id=1261697https://launchpadlibrarian.net/217268516/CVE-2015-5271_puppet-swift.patchhttps://access.redhat.com/errata/RHSA-2015:1862https://bugs.launchpad.net/tripleo/+bug/1494896https://bugzilla.redhat.com/show_bug.cgi?id=1261697https://launchpadlibrarian.net/217268516/CVE-2015-5271_puppet-swift.patch
2016-04-15
Published