PT-2015-5473 · Openstack+1 · Openstack Object Storage+1

Clay Gerrard

·

Published

2015-04-17

·

Updated

2022-05-14

·

CVE-2015-1856

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions OpenStack Object Storage (Swift) versions prior to 2.3.0
Description The issue allows remote authenticated users to delete the latest version of an object by leveraging listing access to the x-versions-location container when allow version is configured.
Recommendations For versions prior to 2.3.0, update to version 2.3.0 or later to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-1856
GHSA-CC77-5VW4-7PWG
RHSA-2015:1681
RHSA-2015:1684
RHSA-2015:1845
RHSA-2015:1846
SUSE-SU-2015:1846-1
USN-2704-1

Affected Products

Openstack Object Storage
Ubuntu