VDB
CVE-2013-4155
CVE-2013-4155
PUBLISHED
CVSS 4 MEDIUM
OpenStack Swift before 1.9.1 in Folsom, Grizzly, and Havana allows authenticated users to cause a denial of service ("superfluous" tombstone consumption and Swift cluster slowdown) via a DELETE request with a timestamp that is older than expected.
EPSS 1.66% · 74.8th percentile
Risk Scores
CVSS 2.0
4
EPSS Score
1.66%
74.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| openstack | folsom | |
| openstack | havana | |
| openstack | grizzly | |
| n/a | n/a | * |
| openstack | swift | 1.1.0, 1.1.0, 1.1.0 |
| PyPI | swift | 0 |
Timeline
- Aug 20, 2013 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
References
- https://bugs.launchpad.net/swift/+bug/1196932 url
- DSA-2737 vendor-advisory
- https://review.openstack.org/#/c/40646/ url
- [oss-security] 20130807 [OSSA 2013-022] Swift Denial of Service using superfluous object tombstones (CVE-2013-4155) mailing-list
- USN-2001-1 vendor-advisory
- https://review.openstack.org/#/c/40645/ url
- https://review.openstack.org/#/c/40643/ url
- RHSA-2013:1197 vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2013-4155 advisory
- https://github.com/openstack/swift/commit/1f4ec235cdfd8c868f2d6458532f9dc32c00b8ca url
- https://github.com/openstack/swift/commit/6b9806e0e8cbec60c0a3ece0bd516e0502827515 url
- https://github.com/openstack/swift package
- https://review.openstack.org/#/c/40643 url
- https://review.openstack.org/#/c/40645 url
- https://review.openstack.org/#/c/40646 url