Openstack · Openstack Object Storage · CVE-2014-0006
**Name of the Vulnerable Software and Affected Versions**
OpenStack Object Storage (Swift) versions 1.4.6 through 1.8.0
OpenStack Object Storage (Swift) versions 1.9.0 through 1.10.0
OpenStack Object Storage (Swift) version 1.11.0
**Description**
The issue allows remote attackers to obtain secret URLs by leveraging an object name and a timing side-channel attack, which is a technique that involves measuring the time it takes for a system to respond to different inputs in order to infer sensitive information.
**Recommendations**
For versions 1.4.6 through 1.8.0, update to a version outside of this range to mitigate the risk.
For versions 1.9.0 through 1.10.0, update to a version outside of this range to mitigate the risk.
For version 1.11.0, update to a version later than 1.11.0 to mitigate the risk.