OSSA-2014-002: Swift TempURL timing attack

Date:

January 16, 2014

CVE:

CVE-2014-0006

Affects

  • Swift: All supported versions

Description

Samuel Merritt from SwiftStack reported a timing attack vulnerability in Swift TempURL middleware. By analyzing response times to arbitrary TempURL requests, an attacker may be able to guess valid secret URLs and get access to objects that were only intended to be publicly shared with specific recipients. In order to use this attack, the attacker needs to know the targeted object name, and the object account needs to have a TempURL key set. Only Swift setups enabling the TempURL middleware are affected.

Patches

Credits

  • Samuel Merritt from SwiftStack (CVE-2014-0006)

References