OpenStack Object Storage (Swift) before 2.3.0, when allow_version is configured, allows remote authenticated users to delete the latest version of an object by leveraging listing access to the x-versions-location container.
References
Configurations
History
No history.
Information
Published : 2015-04-17 17:59
Updated : 2018-01-05 02:30
NVD link : CVE-2015-1856
Mitre link : CVE-2015-1856
CVE.ORG link : CVE-2015-1856
JSON object : View
Products Affected
canonical
- ubuntu_linux
openstack
- swift
CWE
CWE-264
Permissions, Privileges, and Access Controls