CVE-2015-5271

Impact:
Moderate
Public Date:
2015-09-22
CWE:
CWE-285
Bugzilla:
1261697: CVE-2015-5271 openstack-tripleo-heat-templates: unsafe pipeline ordering of swift staticweb middleware
A flaw was discovered in the pipeline ordering of OpenStack Object Storage's staticweb middleware in the swiftproxy configuration generated from the openstack-tripleo-heat-templates package (OpenStack director). The staticweb middleware was incorrectly configured before the Identity Service, and under some conditions an attacker could use this flaw to gain unauthenticated access to private data.

Find out more about CVE-2015-5271 from the MITRE CVE dictionary dictionary and NIST NVD.

CVSS v2 metrics

Base Score 4.3
Base Metrics AV:N/AC:M/Au:N/C:P/I:N/A:N
Access Vector Network
Access Complexity Medium
Authentication None
Confidentiality Impact Partial
Integrity Impact None
Availability Impact None

Find out more about Red Hat support for the Common Vulnerability Scoring System (CVSS).

Red Hat Security Errata

Platform Errata Release Date
OpenStack 7.0 Director for RHEL 7 RHSA-2015:1862 2015-10-08

Affected Packages State

Platform Package State
Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7 openstack-tripleo-heat-templates Will not fix
Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7 instack-undercloud Will not fix

Acknowledgements

This issue was discovered by Christian Schwede and Emilien Macchi of Red Hat.

Last Modified
Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.