---
id: CVE-2015-5223
aliases:
  - GHSA-q45h-chc8-hvp6
  - PYSEC-2026-934
title: OpenStack Object Storage (Swift) Sensitive Data Exposure
summary: OpenStack Object Storage (Swift) Sensitive Data Exposure
severity: medium
vendor: swift
product: swift
ecosystem: pip
affected:
  - swift < 2.4.0
patched:
  - swift 2.4.0
published: '2022-05-14'
updated: '2026-07-07'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-q45h-chc8-hvp6'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2015-5223'
  - url: 'https://bugs.launchpad.net/swift/+bug/1449212'
  - url: 'https://bugs.launchpad.net/swift/+bug/1453948'
  - url: 'https://github.com/openstack/swift'
  - url: 'https://security.openstack.org/ossa/OSSA-2015-016.html'
  - url: >-
      https://web.archive.org/web/20200804233308/http://www.securityfocus.com/bid/84827
  - url: 'http://lists.opensuse.org/opensuse-security-announce/2015-10/msg00025.html'
  - url: 'http://rhn.redhat.com/errata/RHSA-2015-1895.html'
  - url: 'http://rhn.redhat.com/errata/RHSA-2016-0329.html'
  - url: 'http://www.openwall.com/lists/oss-security/2015/08/26/5'
  - url: >-
      http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
tags:
  - osv
  - pip
epss: 0.02605
epssPercentile: 0.84629
ingestedAt: '2026-07-08T18:25:52.086Z'
---

## Overview

OpenStack Object Storage (Swift) before 2.4.0 allows attackers to obtain sensitive information via a PUT tempurl and a DLO object manifest that references an object in another container.

## Affected packages

- `swift < 2.4.0`

## Remediation

Upgrade to a patched release:

- `swift 2.4.0`
