OpenStack Object Storage (Swift) before 2.3.0, when allow_version is configured, allows remote authenticated users to delete the latest version of an object by leveraging listing access to the x-versions-location container.
References
Information
Published : 2015-04-17 10:59
Updated : 2018-01-04 18:30
NVD link : CVE-2015-1856
Mitre link : CVE-2015-1856
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
canonical
- ubuntu_linux
openstack
- swift