CVE-2015-1856

EPSS 0.86%

OpenStack Swift Unauthorized delete of versioned Swift object

Published: 5/14/2022Modified: 4/28/2026
Also known as:DEBIAN-CVE-2015-1856

Description

OpenStack Object Storage (Swift) before 2.3.0, when allow_version is configured, allows remote authenticated users to delete the latest version of an object by leveraging listing access to the x-versions-location container.

Affected packages (2)

References (18)