CVE-2017-8761
MEDIUMOpenstack Swift < 2.10.1 - Information Disclosure
Title source: ruleDescription
In OpenStack Swift through 2.10.1, 2.11.0 through 2.13.0, and 2.14.0, the proxy-server logs full tempurl paths, potentially leaking reusable tempurl signatures to anyone with read access to these logs. All Swift deployments using the tempurl middleware are affected.
Scores
CVSS v3
4.3
EPSS
0.0017
EPSS Percentile
37.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Classification
CWE
CWE-200
Status
published
Affected Products (3)
openstack/swift
< 2.10.1
openstack/swift
pypi/swift
< 2.15.2PyPI
Timeline
Published
Jun 02, 2021
Tracked Since
Feb 18, 2026