CRITICAL · 9.8

CVE-2012-4406

OpenStack Object Storage (swift) before 1.7.0 uses the loads function in the pickle Python module unsafely when storing and loading metadata in memcached, which allows remote attackers to execute arbi...

Vulnerability Description

OpenStack Object Storage (swift) before 1.7.0 uses the loads function in the pickle Python module unsafely when storing and loading metadata in memcached, which allows remote attackers to execute arbitrary code via a crafted pickle object.

CVSS Score

9.8

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
OpenstackSwift< 1.7.0
FedoraprojectFedora16
RedhatGluster Storage Management Console2.0
RedhatGluster Storage Server For On-Premise2.0
RedhatStorage2.0
RedhatStorage For Public Cloud2.0
RedhatEnterprise Linux Server5.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2012-4406?

CVE-2012-4406 is a vulnerability with a CVSS score of 9.8 (CRITICAL). OpenStack Object Storage (swift) before 1.7.0 uses the loads function in the pickle Python module unsafely when storing and loading metadata in memcached, which allows remote attackers to execute arbi...

How severe is CVE-2012-4406?

CVE-2012-4406 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2012-4406?

Check the references section above for vendor advisories and patch information. Affected products include: Openstack Swift, Fedoraproject Fedora, Redhat Gluster Storage Management Console, Redhat Gluster Storage Server For On-Premise, Redhat Storage.