Ubuntu Security Notice (C) 2014 Canonical, Inc. / NASL script (C) 2014 Tenable Network Security, Inc.
The remote Ubuntu host is missing a security-related patch.
John Dickinson discovered that Swift did not properly quote the
WWW-Authenticate header value. If a user were tricked into navigating
to a malicious Swift URL, an attacker could conduct cross-site
scripting attacks. With cross-site scripting vulnerabilities, if a
user were tricked into viewing server output during a crafted server
request, a remote attacker could exploit this to modify the contents,
or steal confidential data, within the same domain.
Update the affected python-swift package.
Risk factor :
Medium / CVSS Base Score : 4.3
CVSS Temporal Score : 3.7
Public Exploit Available : true