Bug 883564 (CVE-2014-3497) - CVE-2014-3497: openstack-swift: XSS in Swift requests through WWW-Authenticate header
Summary: CVE-2014-3497: openstack-swift: XSS in Swift requests through WWW-Authenticat...
Status: RESOLVED INVALID
Alias: CVE-2014-3497
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other openSUSE 13.1
: P5 - None : Normal
Target Milestone: ---
Assignee: Bernhard Wiedemann
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/99944/
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2014-06-20 13:27 UTC by Johannes Segitz
Modified: 2015-04-07 14:57 UTC (History)
2 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Johannes Segitz 2014-06-20 13:27:09 UTC
CVE-2014-3497

The WWW-Authenticate header value (returned on a 401 response) includes user-supplied strings to indicate the proper auth realm. However, Swift un-quotes the URL and then sets the value in the response. This means that a URL can be constructed that includes new HTML content at the hoster's own domain.

Only openSUSE Factory is affected

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-3497
http://people.canonical.com/~ubuntu-security/cve/2014/CVE-2014-3497.html
Comment 2 Bernhard Wiedemann 2014-10-13 08:37:52 UTC
https://bugs.launchpad.net/swift/icehouse/+bug/1327414
https://review.openstack.org/#/q/If8bd8842f2ce821756e9b4461a18a8ac8d42fb8c,n,z

swift is no more in Factory, but I can not find mention of the fix
in our changes files
Comment 3 Johannes Segitz 2015-04-07 14:57:23 UTC
then we can close this bug