CVE Vulnerabilities

CVE-2015-1856

Published: Apr 17, 2015 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.5 MEDIUM
AV:N/AC:L/Au:S/C:N/I:P/A:P
RedHat/V2
3.5 MODERATE
AV:N/AC:M/Au:S/C:N/I:N/A:P
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

OpenStack Object Storage (Swift) before 2.3.0, when allow_version is configured, allows remote authenticated users to delete the latest version of an object by leveraging listing access to the x-versions-location container.

Affected Software

NameVendorStart VersionEnd Version
SwiftOpenstack*2.2.2 (including)
Native Client for RHEL 6 for Red Hat StorageRedHatglusterfs-0:3.7.1-16.el6*
Native Client for RHEL 7 for Red Hat StorageRedHatglusterfs-0:3.7.1-16.el7*
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6RedHatopenstack-swift-0:1.13.1-6.el6ost*
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7RedHatopenstack-swift-0:1.13.1-5.el7ost*
Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7RedHatopenstack-swift-0:2.2.0-4.el7ost*
Red Hat Gluster Storage 3.1 for RHEL 6RedHatgdeploy-0:1.0-12.el6rhs*
Red Hat Gluster Storage 3.1 for RHEL 6RedHatglusterfs-0:3.7.1-16.el6rhs*
Red Hat Gluster Storage 3.1 for RHEL 6RedHatgluster-nagios-addons-0:0.2.5-1.el6rhs*
Red Hat Gluster Storage 3.1 for RHEL 6RedHatgluster-nagios-common-0:0.2.2-1.el6rhs*
Red Hat Gluster Storage 3.1 for RHEL 6RedHatgstatus-0:0.65-1.el6rhs*
Red Hat Gluster Storage 3.1 for RHEL 6RedHatnagios-server-addons-0:0.2.2-1.el6rhs*
Red Hat Gluster Storage 3.1 for RHEL 6RedHatnfs-ganesha-0:2.2.0-9.el6rhs*
Red Hat Gluster Storage 3.1 for RHEL 6RedHatopenstack-swift-0:1.13.1-6.el6ost*
Red Hat Gluster Storage 3.1 for RHEL 6RedHatredhat-storage-server-0:3.1.1.0-2.el6rhs*
Red Hat Gluster Storage 3.1 for RHEL 6RedHatswiftonfile-0:1.13.1-5.el6rhs*
Red Hat Gluster Storage 3.1 for RHEL 6RedHatvdsm-0:4.16.20-1.3.el6rhs*
Red Hat Gluster Storage 3.1 for RHEL 7RedHatgdeploy-0:1.0-12.el7rhgs*
Red Hat Gluster Storage 3.1 for RHEL 7RedHatglusterfs-0:3.7.1-16.el7rhgs*
Red Hat Gluster Storage 3.1 for RHEL 7RedHatgluster-nagios-addons-0:0.2.5-1.el7rhgs*
Red Hat Gluster Storage 3.1 for RHEL 7RedHatgluster-nagios-common-0:0.2.2-1.el7rhgs*
Red Hat Gluster Storage 3.1 for RHEL 7RedHatgstatus-0:0.65-1.el7rhgs*
Red Hat Gluster Storage 3.1 for RHEL 7RedHatnagios-server-addons-0:0.2.2-1.el7rhgs*
Red Hat Gluster Storage 3.1 for RHEL 7RedHatnfs-ganesha-0:2.2.0-9.el7rhgs*
Red Hat Gluster Storage 3.1 for RHEL 7RedHatopenstack-swift-0:1.13.1-6.el7ost*
Red Hat Gluster Storage 3.1 for RHEL 7RedHatredhat-storage-server-0:3.1.1.0-2.el7rhgs*
Red Hat Gluster Storage 3.1 for RHEL 7RedHatswiftonfile-0:1.13.1-5.el7rhgs*
Red Hat Gluster Storage 3.1 for RHEL 7RedHatvdsm-0:4.16.20-1.3.el7rhgs*
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7RedHatglusterfs-0:3.7.1-16.el7*
SwiftUbuntudevel*
SwiftUbuntutrusty*
SwiftUbuntuutopic*
SwiftUbuntuvivid*

References