CVE-2017-8761

MEDIUM

Openstack Swift < 2.10.1 - Information Disclosure

Title source: rule

Description

In OpenStack Swift through 2.10.1, 2.11.0 through 2.13.0, and 2.14.0, the proxy-server logs full tempurl paths, potentially leaking reusable tempurl signatures to anyone with read access to these logs. All Swift deployments using the tempurl middleware are affected.

Scores

CVSS v3 4.3
EPSS 0.0017
EPSS Percentile 37.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Classification

CWE
CWE-200
Status published

Affected Products (3)

openstack/swift < 2.10.1
openstack/swift
pypi/swift < 2.15.2PyPI

Timeline

Published Jun 02, 2021
Tracked Since Feb 18, 2026