CVE-2022-47950
Published on: Not Yet Published
Last Modified on: 01/30/2023 03:09:00 PM UTC
Certain versions of Debian Linux from Debian contain the following vulnerability:
An issue was discovered in OpenStack Swift before 2.28.1, 2.29.x before 2.29.2, and 2.30.0. By supplying crafted XML files, an authenticated user may coerce the S3 API into returning arbitrary file contents from the host server, resulting in unauthorized read access to potentially sensitive data. This impacts both s3api deployments (Rocky or later), and swift3 deployments (Queens and earlier, no longer actively developed).
- CVE-2022-47950 has been assigned by
[email protected] to track the vulnerability - currently rated as MEDIUM severity.
CVSS3 Score: 6.5 - MEDIUM
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | LOW | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | NONE | NONE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
OSSA-2023-001: Arbitrary file access through custom S3 XML entities — OpenStack Security Advisories 0.0.1.dev258 documentation | security.openstack.org text/html |
![]() |
Bug #1998625 “[OSSA-2023-001] Arbitrary file access through cust...” : Bugs : OpenStack Object Storage (swift) | launchpad.net text/html |
![]() |
[SECURITY] [DLA 3281-1] swift security update | lists.debian.org text/html |
![]() |
Related QID Numbers
- 181501 Debian Security Update for swift (DSA 5327-1)
- 181503 Debian Security Update for swift (DLA 3281-1)
- 199167 Ubuntu Security Notification for OpenStack Swift Vulnerability (USN-5852-1)
- 241234 Red Hat Update for OpenStack Platform 17.0 (RHSA-2023:1013)
- 241269 Red Hat Update for multiple OpenStack Platforms (RHSA-2023:1277)
Exploit/POC from Github
An issue was discovered in OpenStack Swift before 2.28.1, 2.29.x before 2.29.2, and 2.30.0. By supplying crafted XML …
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Operating System | Debian | Debian Linux | 10.0 | All | All | All |
Application | Openstack | Swift | All | All | All | All |
Application | Openstack | Swift | 2.30.0 | All | All | All |
- cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*:
- cpe:2.3:a:openstack:swift:*:*:*:*:*:*:*:*:
- cpe:2.3:a:openstack:swift:2.30.0:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2022-47950 : An issue was discovered in OpenStack Swift before 2.28.1, 2.29.x before 2.29.2, and 2.30.0. By sup… twitter.com/i/web/status/1… | 2023-01-18 17:05:00 |
![]() |
CVE-2022-47950 | 2023-01-18 17:40:09 |