Openstack

Swift

18 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.25%
  • Veröffentlicht 05.08.2026 05:05:33
  • Zuletzt bearbeitet 05.08.2026 14:17:12

In OpenStack Swift through 2.38.0, the S3API middleware does not sanitize Swift-native control headers (X-Copy-From, X-Copy-From-Account) from S3 API requests when s3_acl=true. An attacker can inject these headers into a signed PUT request targeting ...

  • EPSS 0.25%
  • Veröffentlicht 05.08.2026 05:01:20
  • Zuletzt bearbeitet 06.08.2026 14:16:41

In OpenStack Swift through 2.38.0, S3API middleware does not enforce that semantic x-amz-* headers are covered by the SigV4 signature on presigned URL requests. An attacker who obtains a presigned PUT URL can inject an unsigned X-Amz-Copy-Source head...

  • EPSS 0.46%
  • Veröffentlicht 05.08.2026 04:54:03
  • Zuletzt bearbeitet 06.08.2026 14:16:41

In OpenStack Swift through 2.38.0, the proxy server Accept header parser contains a regular expression vulnerable to catastrophic backtracking (ReDoS). The "qdtext" pattern (?:[^"]|\\.)* allows an unauthenticated remote attacker to send a crafted Acc...

Exploit
  • EPSS 0.14%
  • Veröffentlicht 23.06.2026 17:03:32
  • Zuletzt bearbeitet 29.06.2026 23:09:33

In OpenStack Swift before 2.37.2, proxy-server does not strip internal update headers (X-Container-Host, X-Container-Device, X-Delete-At-Host, X-Delete-At-Device) from client requests before forwarding them to object-servers. An authenticated user wi...

  • EPSS 0.32%
  • Veröffentlicht 27.05.2026 01:57:58
  • Zuletzt bearbeitet 24.07.2026 12:10:00

In OpenStack Swift before 2.36.2 and 2.37.2, s3api middleware enters an infinite loop when processing a truncated aws-chunked PUT request body. The StreamingInput class repeatedly appends an empty buffer and re-reads, causing the proxy-server worker ...

Exploit
  • EPSS 1.01%
  • Veröffentlicht 18.01.2023 17:15:10
  • Zuletzt bearbeitet 04.04.2025 16:15:16

An issue was discovered in OpenStack Swift before 2.28.1, 2.29.x before 2.29.2, and 2.30.0. By supplying crafted XML files, an authenticated user may coerce the S3 API into returning arbitrary file contents from the host server, resulting in unauthor...

  • EPSS 0.8%
  • Veröffentlicht 02.06.2021 14:15:07
  • Zuletzt bearbeitet 21.11.2024 03:34:38

In OpenStack Swift through 2.10.1, 2.11.0 through 2.13.0, and 2.14.0, the proxy-server logs full tempurl paths, potentially leaking reusable tempurl signatures to anyone with read access to these logs. All Swift deployments using the tempurl middlewa...

  • EPSS 8.42%
  • Veröffentlicht 21.11.2017 13:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

An issue was discovered in middleware.py in OpenStack Swauth through 1.2.0 when used with OpenStack Swift through 2.15.1. The Swift object store and proxy server are saving (unhashed) tokens retrieved from the Swauth middleware authentication mechani...

  • EPSS 3.85%
  • Veröffentlicht 29.01.2016 20:59:03
  • Zuletzt bearbeitet 06.05.2026 22:30:45

OpenStack Object Storage (Swift) before 2.3.1 (Kilo), 2.4.x, and 2.5.x before 2.5.1 (Liberty) do not properly close server connections, which allows remote attackers to cause a denial of service (proxy-server resource consumption) via a series of int...

  • EPSS 3.82%
  • Veröffentlicht 29.01.2016 20:59:02
  • Zuletzt bearbeitet 06.05.2026 22:30:45

OpenStack Object Storage (Swift) before 2.4.0 does not properly close client connections, which allows remote attackers to cause a denial of service (proxy-server resource consumption) via a series of interrupted requests to a Large Object URL.