6.5
CVSSv3

CVE-2022-47950

Published: 18/01/2023 Updated: 07/11/2023
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

An issue exists in OpenStack Swift prior to 2.28.1, 2.29.x prior to 2.29.2, and 2.30.0. By supplying crafted XML files, an authenticated user may coerce the S3 API into returning arbitrary file contents from the host server, resulting in unauthorized read access to potentially sensitive data. This impacts both s3api deployments (Rocky or later), and swift3 deployments (Queens and previous versions, no longer actively developed).

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

openstack swift

openstack swift 2.30.0

debian debian linux 10.0

Vendor Advisories

Synopsis Important: Red Hat OpenStack Platform (openstack-swift) security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for openstack-swift is now available for Red Hat OpenStackPlatformRed Hat Product ...
Debian Bug report logs - #1029154 swift: CVE-2022-47950 Package: src:swift; Maintainer for src:swift is Debian OpenStack <team+openstack@trackerdebianorg>; Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Wed, 18 Jan 2023 16:33:01 UTC Severity: grave Tags: security, upstream Found in version swift/2300-3 ...
Sebastien Meriot discovered that the S3 API of Swift, a distributed virtual object store, was susceptible to information disclosure For the stable distribution (bullseye), this problem has been fixed in version 2260-10+deb11u1 We recommend that you upgrade your swift packages For the detailed security status of swift please refer to its securi ...
Description<!---->A flaw was found in Swift's S3 XML parser By supplying specially crafted XML files, an authenticated user may coerce the S3 API into returning arbitrary file contents from the host server, resulting in unauthorized read access to potentially sensitive data This issue impacts both s3api deployments (Rocky or later) and swift3 dep ...