OpenStack Object Storage (swift) before 1.7.0 uses the loads function in the pickle Python module unsafely when storing and loading metadata in memcached, which allows remote attackers to execute arbitrary code via a crafted pickle object.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
GHSA-v7mh-3jgf-r26c | OpenStack Object Storage (swift) Code Injection vulnerability |
![]() |
USN-1887-1 | OpenStack Swift vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.

Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-06T20:35:09.281Z
Reserved: 2012-08-21T00:00:00
Link: CVE-2012-4406

No data.

Status : Deferred
Published: 2012-10-22T23:55:06.743
Modified: 2025-04-11T00:51:21.963
Link: CVE-2012-4406


No data.