Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
Alistair Coles discovered that the s3api middleware of Swift, a distributed virtual object store, was susceptible to denial of service. The oldstable distribution (bookworm) is not affected. For the stable distribution (trixie), this problem has been fixed in version 2.35.1-0+deb13u2.. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6314-1
OpenStack Swift could be made to expose sensitive information over the network.. =========================================================================Ubuntu Security Notice USN-5852-1 February 09, 2023 swift vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.10 - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS Summary: OpenStack Swift could be made to expose sensitive information over the network. Software Description: - swift: OpenStack distributed virtual object store Details: It was discovered that OpenStack Swift incorrectly handled certain XML files. A remote authenticated user could possibly use this issue to obtain arbitrary file contents containing sensitive information from the server. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 22.10: python3-swift 2.30.1-0ubuntu1 swift 2.30.1-0ubuntu1 Ubuntu 22.04 LTS: python3-swift 2.29.2-0ubuntu1 swift 2.29.2-0ubuntu1 Ubuntu 20.04 LTS: python3-swift 2.25.2-0ubuntu1.1 swift 2.25.2-0ubuntu1.1 This update uses a new upstream release, which includes additional bug fixes. In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5852-1 CVE-2022-47950 Package Information: https://launchpad.net/ubuntu/+source/swift/2.30.1-0ubuntu1 https://launchpad.net/ubuntu/+source/swift/2.29.2-0ubuntu1 https://launchpad.net/ubuntu/+source/swift/2.25.2-0ubuntu1.1 . High severity security advisory for Ubuntu users: A vulnerability may lead to data leaks. Update systems and follow mitigation steps to protect sensitive info. OpenStack Swift Security, Ubuntu Swift, Swift Vulnerability. . Severity: Critical.LinuxSecurity.com Team
Sebastien Meriot discovered that the S3 API of Swift, a distributed virtual object store, was susceptible to information disclosure. For Debian 10 buster, this problem has been fixed in version . - ----------------------------------------------------------------------- Debian LTS Advisory DLA-3281-1
Sebastien Meriot discovered that the S3 API of Swift, a distributed virtual object store, was susceptible to information disclosure. For the stable distribution (bullseye), this problem has been fixed in . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5327-1
Several security issues were fixed in Swift.. =========================================================================Ubuntu Security Notice USN-2704-1 August 06, 2015 swift vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 15.04 - Ubuntu 14.04 LTS - Ubuntu 12.04 LTS Summary: Several security issues were fixed in Swift. Software Description: - swift: OpenStack distributed virtual object store Details: Rajaneesh Singh discovered Swift does not properly enforce metadata limits. An attacker could abuse this issue to store more metadata than allowed by policy. (CVE-2014-7960) Clay Gerrard discovered Swift allowed users to delete the latest version of object regardless of object permissions when allow_version is configured. An attacker could use this issue to delete objects. (CVE-2015-1856) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 15.04: swift 2.2.2-0ubuntu1.3 Ubuntu 14.04 LTS: swift 1.13.1-0ubuntu1.2 Ubuntu 12.04 LTS: swift 1.4.8-0ubuntu2.5 After a standard system update you need to restart swift to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-2704-1 CVE-2014-7960, CVE-2015-1856 Package Information: https://launchpad.net/ubuntu/+source/swift/2.2.2-0ubuntu1.3 https://launchpad.net/ubuntu/+source/swift/1.13.1-0ubuntu1.2 https://launchpad.net/ubuntu/+source/swift/1.4.8-0ubuntu2.5 . Multiple vulnerabilities addressed in Swift applications affect Ubuntu versions 12.04, 14.04, and 15.04, necessitating urgent patches.. Ubuntu Swift Security, Object Store Vulnerabilities, Update Instructions. . LinuxSecurity.com Team
Swift did not properly perform input validation of certain HTTP headers.. =========================================================================Ubuntu Security Notice USN-2256-1 June 25, 2014 swift vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 14.04 LTS Summary: Swift did not properly perform input validation of certain HTTP headers. Software Description: - swift: OpenStack distributed virtual object store Details: John Dickinson discovered that Swift did not properly quote the WWW-Authenticate header value. If a user were tricked into navigating to a malicious Swift URL, an attacker could conduct cross-site scripting attacks. With cross-site scripting vulnerabilities, if a user were tricked into viewing server output during a crafted server request, a remote attacker could exploit this to modify the contents, or steal confidential data, within the same domain. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 14.04 LTS: python-swift 1.13.1-0ubuntu1.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-2256-1 CVE-2014-3497 Package Information: https://launchpad.net/ubuntu/+source/swift/1.13.1-0ubuntu1.1 . Swift for Linux may be vulnerable due to flawed input sanitization, resulting in Cross-Site Scripting (XSS) vulnerabilities. Apply updates to address potential security risks.. Ubuntu Swift Update, Cross Site Scripting, Input Validation Risk. . Severity: Critical. LinuxSecurity.com Team
Updated openstack-swift packages that fix one security issue are now available for Red Hat Enterprise Linux OpenStack Platform 3.0. The Red Hat Security Response Team has rated this update as having Moderate [More...]. ==================================================================== Red Hat Security Advisory Synopsis: Moderate: openstack-swift security update Advisory ID: RHSA-2014:0367-01 Product: Red Hat OpenStack Advisory URL: https://access.redhat.com/errata/RHSA-2014:0367.html Issue date: 2014-04-03 CVE Names: CVE-2014-0006 ==================================================================== 1. Summary: Updated openstack-swift packages that fix one security issue are now available for Red Hat Enterprise Linux OpenStack Platform 3.0. The Red Hat Security Response Team has rated this update as having Moderate security impact. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available from the CVE link in the References section. 2. Relevant releases/architectures: OpenStack 3 - noarch 3. Description: OpenStack Object Storage (swift) provides object storage in virtual containers, which allows users to store and retrieve files (arbitrary data). The service's distributed architecture supports horizontal scaling; redundancy as failure-proofing is provided through software-based data replication. Because Object Storage supports asynchronous eventual consistency replication, it is well suited to multiple data-center deployment. A timing attack flaw was found in the way the swift TempURL middleware responded to arbitrary TempURL requests. An attacker with knowledge of an object's name could use this flaw to obtain a secret URL to this object, which was intended to be publicly shared only with specific recipients, if the object had the TempURL key set. Note that only setups using the TempURL middleware were affected. (CVE-2014-0006) Red Hat would like to thank the OpenStack Project forreporting this issue. Upstream acknowledges Samuel Merritt of SwiftStack as the original reporter. All users of openstack-swift are advised to upgrade to these updated packages, which correct this issue. After installing this update, the OpenStack Object Storage services will be restarted automatically. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at https://access.redhat.com/site/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1051670 - CVE-2014-0006 Openstack Swift: TempURL timing attack 6. Package List: OpenStack 3: Source: noarch: openstack-swift-1.8.0-8.el6ost.noarch.rpm openstack-swift-account-1.8.0-8.el6ost.noarch.rpm openstack-swift-container-1.8.0-8.el6ost.noarch.rpm openstack-swift-doc-1.8.0-8.el6ost.noarch.rpm openstack-swift-object-1.8.0-8.el6ost.noarch.rpm openstack-swift-proxy-1.8.0-8.el6ost.noarch.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key#package 7. References: https://access.redhat.com/security/cve/CVE-2014-0006 https://access.redhat.com/security/updates/classification#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2014 Red Hat, Inc. . Canonical has issued a critical notice for kubernetes with a vulnerability patch. Update your installations immediately.. OpenStack Security, Red Hat Advisory, Object Storage, Swift Update. . Severity: Important. LinuxSecurity.com Team
Updated openstack-swift packages that fix one security issue are now available for Red Hat Enterprise Linux OpenStack Platform 4.0. The Red Hat Security Response Team has rated this update as having Moderate security impact. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: openstack-swift security update Advisory ID: RHSA-2014:0232-01 Product: Red Hat OpenStack Advisory URL: https://access.redhat.com/errata/RHSA-2014:0232.html Issue date: 2014-03-04 CVE Names: CVE-2014-0006 ==================================================================== 1. Summary: Updated openstack-swift packages that fix one security issue are now available for Red Hat Enterprise Linux OpenStack Platform 4.0. The Red Hat Security Response Team has rated this update as having Moderate security impact. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available from the CVE link in the References section. 2. Relevant releases/architectures: OpenStack 4 - noarch 3. Description: OpenStack Object Storage (swift) provides object storage in virtual containers, which allows users to store and retrieve files (arbitrary data). The service's distributed architecture supports horizontal scaling; redundancy as failure-proofing is provided through software-based data replication. Because Object Storage supports asynchronous eventual consistency replication, it is well suited to multiple data-center deployment. A timing attack flaw was found in the way the swift TempURL middleware responded to arbitrary TempURL requests. An attacker with knowledge of an object's name could use this flaw to obtain a secret URL to this object, which was intended to be publicly shared only with specific recipients, if the object had the TempURL key set. Note that only setups usingthe TempURL middleware were affected. (CVE-2014-0006) Red Hat would like to thank the Openstack Project for reporting this issue. Upstream acknowledges Samuel Merritt of SwiftStack as the original reporter. All users of openstack-swift are advised to upgrade to these updated packages, which correct this issue. After installing this update, the OpenStack Object Storage services will be restarted automatically. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at https://access.redhat.com/site/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1051670 - CVE-2014-0006 Openstack Swift: TempURL timing attack 6. Package List: OpenStack 4: Source: noarch: openstack-swift-1.10.0-3.el6ost.noarch.rpm openstack-swift-account-1.10.0-3.el6ost.noarch.rpm openstack-swift-container-1.10.0-3.el6ost.noarch.rpm openstack-swift-doc-1.10.0-3.el6ost.noarch.rpm openstack-swift-object-1.10.0-3.el6ost.noarch.rpm openstack-swift-proxy-1.10.0-3.el6ost.noarch.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key#package 7. References: https://access.redhat.com/security/cve/CVE-2014-0006 https://access.redhat.com/security/updates/classification#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2014 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.4 (GNU/Linux) iD8DBQFTFip6XlSAg2UNWIIRAo6pAJwPy3nfKn4SPNO5u+8rNpRbtBnrXwCfZZsF qHpypUHyvx3KkcU7IVIBPI4=EwJL -----END PGP SIGNATURE----- -- Enterprise-watch-list mailing list
Get the latest Linux and open source security news straight to your inbox.