Oval Definition:oval:com.ubuntu.artful:def:201716613000
Revision Date:2017-11-21Version:1
Title:CVE-2017-16613 on Ubuntu 17.10 (artful) - medium.
Description:An issue was discovered in middleware.py in OpenStack Swauth through 1.2.0 when used with OpenStack Swift through 2.15.1. The Swift object store and proxy server are saving (unhashed) tokens retrieved from the Swauth middleware authentication mechanism to a log file as part of a GET URI. This allows attackers to bypass authentication by inserting a token into an X-Auth-Token header of a new request. NOTE: github.com/openstack/swauth URLs do not mean that Swauth is maintained by an official OpenStack project team.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2017-16613
Platform(s):Ubuntu 17.10
Product(s):
Definition Synopsis
  • Ubuntu 17.10 (artful) is installed.
  • AND The vulnerability of the 'swauth' package in artful is not known (status: 'needs-triage'). It is pending evaluation.
  • BACK