The TempURL middleware in OpenStack Object Storage (Swift) 1.4.6 through 1.8.0, 1.9.0 through 1.10.0, and 1.11.0 allows remote attackers to obtain secret URLs by leveraging an object name and a timing side-channel attack.
{
"severity": "HIGH",
"nvd_published_at": "2014-01-23T01:55:00Z",
"github_reviewed_at": "2023-08-16T23:22:49Z",
"cwe_ids": [
"CWE-200"
],
"github_reviewed": true
}