{"affected":[{"ecosystem_specific":{"binaries":[{"openstack-swift":"2.1.0-11.1","openstack-swift-account":"2.1.0-11.1","openstack-swift-container":"2.1.0-11.1","openstack-swift-doc":"2.1.0-11.1","openstack-swift-object":"2.1.0-11.1","openstack-swift-proxy":"2.1.0-11.1","python-swift":"2.1.0-11.1"}]},"package":{"ecosystem":"SUSE:OpenStack Cloud 5","name":"openstack-swift","purl":"pkg:rpm/suse/openstack-swift&distro=SUSE%20OpenStack%20Cloud%205"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.1.0-11.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"openstack-swift":"2.1.0-11.1","openstack-swift-account":"2.1.0-11.1","openstack-swift-container":"2.1.0-11.1","openstack-swift-doc":"2.1.0-11.1","openstack-swift-object":"2.1.0-11.1","openstack-swift-proxy":"2.1.0-11.1","python-swift":"2.1.0-11.1"}]},"package":{"ecosystem":"SUSE:OpenStack Cloud 5","name":"openstack-swift-doc","purl":"pkg:rpm/suse/openstack-swift-doc&distro=SUSE%20OpenStack%20Cloud%205"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.1.0-11.1"}],"type":"ECOSYSTEM"}]}],"aliases":[],"details":"openstack-swift was updated to fix three security issues.\n\nThese security issues were fixed:\n- CVE-2015-1856: OpenStack Object Storage (Swift), when allow_version is configured, allowed remote authenticated users to delete the latest version of an object by leveraging listing access to the x-versions-location container (bsc#927793).\n- CVE-2014-7960: OpenStack Object Storage (Swift) allowed remote authenticated users to bypass the max_meta_count and other metadata constraints via multiple crafted requests which exceed the limit when combined (bsc#900253).\n- CVE-2015-5223: Information leak via Swift tempurls (bsc#942641).\n  ","id":"SUSE-SU-2015:1846-1","modified":"2015-10-19T09:00:52Z","published":"2015-10-19T09:00:52Z","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2015/suse-su-20151846-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/900253"},{"type":"REPORT","url":"https://bugzilla.suse.com/927793"},{"type":"REPORT","url":"https://bugzilla.suse.com/942641"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2014-7960"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2015-1856"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2015-5223"}],"related":["CVE-2014-7960","CVE-2015-1856","CVE-2015-5223"],"summary":"Security update for openstack-swift","upstream":["CVE-2014-7960","CVE-2015-1856","CVE-2015-5223"]}