CVE-2016-0738

Severity CVSS v4.0:
Pending analysis
Type:
CWE-399 Resource Management Errors
Publication date:
29/01/2016
Last modified:
12/04/2025

Description

OpenStack Object Storage (Swift) before 2.3.1 (Kilo), 2.4.x, and 2.5.x before 2.5.1 (Liberty) do not properly close server connections, which allows remote attackers to cause a denial of service (proxy-server resource consumption) via a series of interrupted requests to a Large Object URL.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:openstack:swift:*:*:*:*:*:*:*:* 2.3.0 (including)
cpe:2.3:a:openstack:swift:2.4.0:*:*:*:*:*:*:*
cpe:2.3:a:openstack:swift:2.5.0:*:*:*:*:*:*:*