Bugzilla – Bug 883564
CVE-2014-3497: openstack-swift: XSS in Swift requests through WWW-Authenticate header
Last modified: 2015-04-07 14:57:23 UTC
CVE-2014-3497 The WWW-Authenticate header value (returned on a 401 response) includes user-supplied strings to indicate the proper auth realm. However, Swift un-quotes the URL and then sets the value in the response. This means that a URL can be constructed that includes new HTML content at the hoster's own domain. Only openSUSE Factory is affected References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-3497 http://people.canonical.com/~ubuntu-security/cve/2014/CVE-2014-3497.html
https://bugs.launchpad.net/swift/icehouse/+bug/1327414 https://review.openstack.org/#/q/If8bd8842f2ce821756e9b4461a18a8ac8d42fb8c,n,z swift is no more in Factory, but I can not find mention of the fix in our changes files
then we can close this bug