Vulnerability CVE-2015-5271


Published: 2016-04-15

Description:
The TripleO Heat templates (tripleo-heat-templates) do not properly order the Identity Service (keystone) before the OpenStack Object Storage (Swift) staticweb middleware in the swiftproxy pipeline when the staticweb middleware is enabled, which might allow remote attackers to obtain sensitive information from private containers via unspecified vectors.

CVSS2 => (AV:N/AC:L/Au:N/C:P/I:N/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
5/10
2.9/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
None
None
Affected software
Redhat -> Openstack 
Openstack -> Tripleo heat templates 

 References:
https://launchpadlibrarian.net/217268516/CVE-2015-5271_puppet-swift.patch
https://bugzilla.redhat.com/show_bug.cgi?id=1261697
https://bugs.launchpad.net/tripleo/+bug/1494896
https://access.redhat.com/errata/RHSA-2015:1862

Copyright 2024, cxsecurity.com

 

Back to Top