cbcvebase.
CVE-2017-8761
published 2021-06-02

CVE-2017-8761: In OpenStack Swift through 2.10.1, 2.11.0 through 2.13.0, and 2.14.0, the proxy-server logs full tempurl paths, potentially leaking reusable tempurl signatures…

PriorityP421medium4.3CVSS 3.1
AVNACLPRLUINSUCLINAN
EPSS
0.79%
52.2th percentile
In OpenStack Swift through 2.10.1, 2.11.0 through 2.13.0, and 2.14.0, the proxy-server logs full tempurl paths, potentially leaking reusable tempurl signatures to anyone with read access to these logs. All Swift deployments using the tempurl middleware are affected.

Affected

9 ranges
VendorProductVersion rangeFixed in
debianswift< swift 2.17.0-2 (bookworm)swift 2.17.0-2 (bookworm)
openstackswift<= 2.10.1
openstackswift
openstackswift>= 0 < 2.17.0-22.17.0-2
openstackswift>= 0 < 2.17.0-22.17.0-2
openstackswift>= 0 < 2.17.0-22.17.0-2
openstackswift>= 0 < 2.17.0-22.17.0-2
openstackswift>= 0 < 2.15.22.15.2
openstackswift2.11.0 – 2.13.0

CVSS provenance

nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.