VulnerabilityModified
CVE-2014-0006
The TempURL middleware in OpenStack Object Storage (Swift) 1.4.6 through 1.8.0, 1.9.0 through 1.10.0, and 1.11.0 allows remote attackers to obtain secret URLs by leveraging an object name and a timing side-channel attack.
MEDIUM 4.3EPSS 1.91%
Does this matter?
Lower severity and a low EPSS score (1.91%). Track it; it rarely justifies an emergency change on its own.
Description
The TempURL middleware in OpenStack Object Storage (Swift) 1.4.6 through 1.8.0, 1.9.0 through 1.10.0, and 1.11.0 allows remote attackers to obtain secret URLs by leveraging an object name and a timing side-channel attack.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
- EPSS
- 1.91% probability · 79th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- openstack/swift
- Source
- secalert@redhat.com
References
- http://rhn.redhat.com/errata/RHSA-2014-0232.html
- http://www.openwall.com/lists/oss-security/2014/01/17/5Patch
- https://bugs.launchpad.net/swift/+bug/1265665Vendor Advisory
- http://rhn.redhat.com/errata/RHSA-2014-0232.html
- http://www.openwall.com/lists/oss-security/2014/01/17/5Patch
- https://bugs.launchpad.net/swift/+bug/1265665Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.