peter bassill · operator
$ cve CVE-2012-4406 JSON

CVE-2012-4406

9.8
CRITICAL · CVSS 3.1 · EPSS 6.6% (pctl 94)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

OpenStack Object Storage (swift) before 1.7.0 uses the loads function in the pickle Python module unsafely when storing and loading metadata in memcached, which allows remote attackers to execute arbitrary code via a crafted pickle object.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS6.57% — more likely to be exploited than 94% of all CVEs
WeaknessCWE-502
On CISA KEVno
Public exploitnone known
Published2012-10-22
Last modified2026-06-16

Affected (7)

VendorProduct
fedoraprojectfedora
openstackswift
redhatenterprise linux server
redhatgluster storage management console
redhatgluster storage server for on-premise
redhatstorage
redhatstorage for public cloud

References

→ the Explorer  ·  watch your stack  ·  NVD