CVE-2015-5271
Last modified
CVE-2015-5271 is a vulnerability of currently unknown severity. The TripleO Heat templates (tripleo-heat-templates) do not properly order the Identity Service (keystone) before the OpenStack Object Storage (Swift) staticweb middleware in the swiftproxy pipeline when the staticweb middleware is enabled, which might allow remote attackers to obtain sensitive information from private containers via unspecified vectors.. EPSS estimates a 2.42% chance of exploitation in the next 30 days.
Description
The TripleO Heat templates (tripleo-heat-templates) do not properly order the Identity Service (keystone) before the OpenStack Object Storage (Swift) staticweb middleware in the swiftproxy pipeline when the staticweb middleware is enabled, which might allow remote attackers to obtain sensitive information from private containers via unspecified vectors.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Openstack | 7.0 |
| Openstack | Tripleo Heat Templates | All versions |
References
- https://access.redhat.com/errata/RHSA-2015:1862Vendor Advisory
- https://access.redhat.com/errata/RHSA-2015:1862Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2015-5271?
How severe is CVE-2015-5271?
How do I fix CVE-2015-5271?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2015
- CVE-2015-5265The wiki component in Moodle through 2.6.11, 2.7.x before 2.…
- CVE-2015-5266The enrol_meta_sync function in enrol/meta/locallib.php in M…
- CVE-2015-5267lib/moodlelib.php in Moodle through 2.6.11, 2.7.x before 2.7…
- CVE-2015-5268The rating component in Moodle through 2.6.11, 2.7.x before …
- CVE-2015-5269Cross-site scripting (XSS) vulnerability in group/overview.p…
- CVE-2015-5270Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2015-5272The Forum module in Moodle 2.7.x before 2.7.10 allows remote…
- CVE-2015-5273The abrt-action-install-debuginfo-to-abrt-cache help program…
- CVE-2015-5274rubygem-openshift-origin-console in Red Hat OpenShift 2.2 al…
- CVE-2015-5275Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2015-5276The std::random_device class in libstdc++ in the GNU Compile…
- CVE-2015-5277The get_contents function in nss_files/files-XXX.c in the Na…
Are you affected by CVE-2015-5271?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
