In OpenStack Swift through 2.10.1, 2.11.0 through 2.13.0, and 2.14.0, the proxy-server logs full tempurl paths, potentially leaking reusable tempurl signatures to anyone with read access to these logs. All Swift deployments using the tempurl middleware are affected.
{
"cpe": [
"cpe:2.3:a:openstack:swift:*:*:*:*:*:*:*:*",
"cpe:2.3:a:openstack:swift:2.14.0:*:*:*:*:*:*:*"
],
"source": [
"CPE_RANGE",
"CPE_STRING"
],
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "2.10.1"
},
{
"introduced": "2.11.0"
},
{
"last_affected": "2.13.0"
},
{
"introduced": "2.14.0"
},
{
"last_affected": "2.14.0"
}
]
}