Vulnerability Name: | CVE-2014-3497 (CCN-94089) | ||||||||||||||||
Assigned: | 2014-06-26 | ||||||||||||||||
Published: | 2014-06-26 | ||||||||||||||||
Updated: | 2023-02-13 | ||||||||||||||||
Summary: | OpenStack Swift is vulnerable to cross-site scripting, caused by improper validation of user-supplied input by the passed to the WWW-Authenticate header. A remote attacker could exploit this vulnerability using a specially-crafted URL to execute script in a victim's Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials. | ||||||||||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N) 3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
| ||||||||||||||||
Vulnerability Consequences: | Cross-Site Scripting | ||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2014-3497 Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com Source: CCN Type: IBM Security Bulletin 1021238 IBM Cloud Manager with Openstack XSS in Swift vulnerability (CVE-2014-3497) Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com Source: CCN Type: OSVDB ID: 108276 OpenStack Swift WWW-Authenticate Header Reflected XSS Source: CCN Type: BID-68116 Openstack Swift 'WWW-Authenticate' Header Cross Site Scripting Vulnerability Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com Source: CCN Type: OSSA 2014-020 www-authenticate value isn't quoted (CVE-2014-3497) Source: CCN Type: Red Hat Bugzilla Bug 1110809 CVE-2014-3497 openstack-swift: XSS in Swift requests through WWW-Authenticate header Source: XF Type: UNKNOWN openstack-swift-cve20143497-xss(94089) Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com | ||||||||||||||||
Vulnerable Configuration: | Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||
Oval Definitions | |||||||||||||||||
| |||||||||||||||||
BACK |