CVE-2015-5242: Red Hat Gluster Storage

Medium severity, CVSS 6.0. EPSS: 2.2% chance of exploitation in the next 30 days.

OpenStack Swift-on-File (aka Swiftonfile) does not properly restrict use of the pickle Python module when loading metadata, which allows remote authenticated users to execute arbitrary code via a crafted extended attribute (xattrs).

Affected products

  • Red Hat Gluster Storage: version 3.1 only

Published 2015-11-25. Last modified 2026-06-17.