Information Exposure Affecting swift package, versions [,2.15.2)
Threat Intelligence
EPSS
0.05% (25th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-PYTHON-SWIFT-1299111
- published 3 Jun 2021
- disclosed 3 Jun 2021
- credit Christian Schwede
Introduced: 3 Jun 2021
CVE-2017-8761 Open this link in a new tabHow to fix?
Upgrade swift
to version 2.15.2 or higher.
Overview
swift is an OpenStack Object Storage
Affected versions of this package are vulnerable to Information Exposure. The proxy-server
logs full tempurl
paths, potentially leaking reusable tempurl
signatures to anyone with read access to these logs. All Swift deployments using the tempurl
middleware are affected.
References
CVSS Scores
version 3.1