Log Path Disclosure in OpenStack Swift by OpenStack Foundation
CVE-2017-8761
4.3MEDIUM
What is CVE-2017-8761?
In OpenStack Swift versions 2.10.1 through 2.14.0, the proxy-server may log full temporary URL paths. This flaw can potentially expose reusable temporary URL signatures to individuals who have read access to the logs. Deployments utilizing the tempurl middleware feature are at risk, as they may inadvertently leak sensitive information from server logs, emphasizing the need for heightened logging and access control measures.