Skip to main content

Vendor/product archive

openstack / swift CVEs

Beta · best-effort

15 CVEs tagged to openstack / swift2 Critical, 2 High, 10 Medium, 1 Low, 0 Unrated.

CVE-2026-50221

Published Jun 23, 2026

In OpenStack Swift before 2.37.2, proxy-server does not strip internal update headers (X-Container-Host, X-Container-Device, X-Delete-At-Host, X-Delete-At-Device) from client requ…

CVSS 5.3 · Medium
evidence mentions
4
Buzz score
27.6
Vendor/product tagsBeta · best-effort

CVE-2022-47950

Published Jan 18, 2023

An issue was discovered in OpenStack Swift before 2.28.1, 2.29.x before 2.29.2, and 2.30.0. By supplying crafted XML files, an authenticated user may coerce the S3 API into return…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-8761

Published Jun 2, 2021

In OpenStack Swift through 2.10.1, 2.11.0 through 2.13.0, and 2.14.0, the proxy-server logs full tempurl paths, potentially leaking reusable tempurl signatures to anyone with read…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-0738

Published Jan 29, 2016

OpenStack Object Storage (Swift) before 2.3.1 (Kilo), 2.4.x, and 2.5.x before 2.5.1 (Liberty) do not properly close server connections, which allows remote attackers to cause a de…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-0737

Published Jan 29, 2016

OpenStack Object Storage (Swift) before 2.4.0 does not properly close client connections, which allows remote attackers to cause a denial of service (proxy-server resource consump…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-5223

Published Oct 26, 2015

OpenStack Object Storage (Swift) before 2.4.0 allows attackers to obtain sensitive information via a PUT tempurl and a DLO object manifest that references an object in another con…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-1856

Published Apr 17, 2015

OpenStack Object Storage (Swift) before 2.3.0, when allow_version is configured, allows remote authenticated users to delete the latest version of an object by leveraging listing…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-7960

Published Oct 17, 2014

OpenStack Object Storage (Swift) before 2.2.0 allows remote authenticated users to bypass the max_meta_count and other metadata constraints via multiple crafted requests which exc…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-3497

Published Jul 3, 2014

Cross-site scripting (XSS) vulnerability in OpenStack Swift 1.11.0 through 1.13.1 allows remote attackers to inject arbitrary web script or HTML via the WWW-Authenticate header.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6396

Published Feb 18, 2014

The OpenStack Python client library for Swift (python-swiftclient) 1.0 through 1.9.0 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0006

Published Jan 23, 2014

The TempURL middleware in OpenStack Object Storage (Swift) 1.4.6 through 1.8.0, 1.9.0 through 1.10.0, and 1.11.0 allows remote attackers to obtain secret URLs by leveraging an obj…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-15 of 15 CVEsPage 1 of 1