affected: - package: ecosystem: PyPI name: swift purl: pkg:pypi/swift ranges: - events: - introduced: 1.4.6 - fixed: 1.12.0 type: ECOSYSTEM versions: - 1.11.0 aliases: - CVE-2014-0006 - GHSA-cf9m-q836-vf26 details: The TempURL middleware in OpenStack Object Storage (Swift) 1.4.6 through 1.8.0, 1.9.0 through 1.10.0, and 1.11.0 allows remote attackers to obtain secret URLs by leveraging an object name and a timing side-channel attack. id: PYSEC-2014-116 modified: '2024-11-25T18:35:18.357593Z' published: '2014-01-23T01:55:00Z' references: - type: ADVISORY url: https://bugs.launchpad.net/swift/+bug/1265665 - type: FIX url: http://www.openwall.com/lists/oss-security/2014/01/17/5 - type: ADVISORY url: http://rhn.redhat.com/errata/RHSA-2014-0232.html