Remote Authentication Vulnerability in OpenStack Object Storage by OpenStack
CVE-2015-1856

Currently unrated

Key Information:

Vendor

Openstack

Status
Vendor
CVE Published:
17 April 2015

What is CVE-2015-1856?

OpenStack Object Storage (Swift) prior to version 2.3.0 features a critical access control vulnerability that permits remote authenticated users to exploit permissions related to versioned objects. Specifically, when the 'allow_version' setting is enabled, a malicious user can delete the latest version of any object by merely possessing listing access to the 'x-versions-location' container, thereby compromising data integrity and availability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.