{"id":"CVE-2015-5223","aliases":["GHSA-q45h-chc8-hvp6","PYSEC-2026-934"],"title":"OpenStack Object Storage (Swift) Sensitive Data Exposure","summary":"OpenStack Object Storage (Swift) Sensitive Data Exposure","severity":"medium","vendor":"swift","product":"swift","ecosystem":"pip","affected":["swift < 2.4.0"],"patched":["swift 2.4.0"],"published":"2022-05-14","updated":"2026-07-07","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-q45h-chc8-hvp6","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2015-5223"},{"url":"https://bugs.launchpad.net/swift/+bug/1449212"},{"url":"https://bugs.launchpad.net/swift/+bug/1453948"},{"url":"https://github.com/openstack/swift"},{"url":"https://security.openstack.org/ossa/OSSA-2015-016.html"},{"url":"https://web.archive.org/web/20200804233308/http://www.securityfocus.com/bid/84827"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2015-10/msg00025.html"},{"url":"http://rhn.redhat.com/errata/RHSA-2015-1895.html"},{"url":"http://rhn.redhat.com/errata/RHSA-2016-0329.html"},{"url":"http://www.openwall.com/lists/oss-security/2015/08/26/5"},{"url":"http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html"}],"tags":["osv","pip"],"epss":0.02605,"epssPercentile":0.84629,"ingestedAt":"2026-07-08T18:25:52.086Z","slug":"CVE-2015-5223","body":"## Overview\n\nOpenStack Object Storage (Swift) before 2.4.0 allows attackers to obtain sensitive information via a PUT tempurl and a DLO object manifest that references an object in another container.\n\n## Affected packages\n\n- `swift < 2.4.0`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `swift 2.4.0`","depth":"sunlit","depthScore":28,"depthScoreParts":{"impact":27.5,"likelihood":0.5,"exploitation":0,"ransomware":0},"changes":[]}