OpenStack Object Storage (swift) Code Injection vulnerability
Critical severity
GitHub Reviewed
Published
May 17, 2022
to the GitHub Advisory Database
•
Updated Feb 6, 2024
Description
Published by the National Vulnerability Database
Oct 22, 2012
Published to the GitHub Advisory Database
May 17, 2022
Reviewed
Feb 8, 2023
Last updated
Feb 6, 2024
OpenStack Object Storage (swift) before 1.7.0 uses the loads function in the pickle Python module unsafely when storing and loading metadata in memcached, which allows remote attackers to execute arbitrary code via a crafted pickle object.
References