CVE-2022-47950
published 2023-01-18CVE-2022-47950: An issue was discovered in OpenStack Swift before 2.28.1, 2.29.x before 2.29.2, and 2.30.0. By supplying crafted XML files, an authenticated user may coerce…
PriorityP339medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
1.00%
58.9th percentile
An issue was discovered in OpenStack Swift before 2.28.1, 2.29.x before 2.29.2, and 2.30.0. By supplying crafted XML files, an authenticated user may coerce the S3 API into returning arbitrary file contents from the host server, resulting in unauthorized read access to potentially sensitive data. This impacts both s3api deployments (Rocky or later), and swift3 deployments (Queens and earlier, no longer actively developed).
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | swift | < swift 2.30.0-4 (bookworm) | swift 2.30.0-4 (bookworm) |
| openstack | swift | < 2.28.1 | 2.28.1 |
| openstack | swift | — | — |
| openstack | swift | >= 0 < 2.26.0-10+deb11u1 | 2.26.0-10+deb11u1 |
| openstack | swift | >= 0 < 2.30.0-4 | 2.30.0-4 |
| openstack | swift | >= 0 < 2.30.0-4 | 2.30.0-4 |
| openstack | swift | >= 0 < 2.30.0-4 | 2.30.0-4 |
| openstack | swift | >= 0 < 2.28.1 | 2.28.1 |
| openstack | swift | >= 2.29.0 < 2.29.2 | 2.29.2 |
| openstack | swift | >= 2.29.0 < 2.29.2 | 2.29.2 |
| openstack | swift | >= 2.30.0 < 2.30.1 | 2.30.1 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
OpenStack Swift vulnerability
vendor_ubuntu·2023-02-09
CVE-2022-47950 OpenStack Swift vulnerability
Title: OpenStack Swift vulnerability
Summary: OpenStack Swift could be made to expose sensitive information over the
network.
It was discovered that OpenStack Swift incorrectly handled certain XML
files. A remote authenticated user could possibly use this issue to obtain
arbitrary file contents containing sensitive information from the server.
Instructions: This update uses a new upstream release, which includes additional bug
fixes. In general, a standard system update will make all the necessary
changes.
Red Hat
openstack-swift: Arbitrary file access through custom S3 XML entities
vendor_redhat·2023-01-17·CVSS 6.5
CVE-2022-47950 [MEDIUM] CWE-552 openstack-swift: Arbitrary file access through custom S3 XML entities
openstack-swift: Arbitrary file access through custom S3 XML entities
An issue was discovered in OpenStack Swift before 2.28.1, 2.29.x before 2.29.2, and 2.30.0. By supplying crafted XML files, an authenticated user may coerce the S3 API into returning arbitrary file contents from the host server, resulting in unauthorized read access to potentially sensitive data. This impacts both s3api deployments (Rocky or later), and swift3 deployments (Queens and earlier, no longer actively developed).
A flaw was found in Swift's S3 XML parser. By supplying specially crafted XML files, an authenticated user may coerce the S3 API into returning arbitrary file contents from the host server, resulting in unauthorized read access to potentially sensitive data. This issue impacts both s3api deployments
Debian
CVE-2022-47950: swift - An issue was discovered in OpenStack Swift before 2.28.1, 2.29.x before 2.29.2, ...
vendor_debian·2022·CVSS 6.5
CVE-2022-47950 [MEDIUM] CVE-2022-47950: swift - An issue was discovered in OpenStack Swift before 2.28.1, 2.29.x before 2.29.2, ...
An issue was discovered in OpenStack Swift before 2.28.1, 2.29.x before 2.29.2, and 2.30.0. By supplying crafted XML files, an authenticated user may coerce the S3 API into returning arbitrary file contents from the host server, resulting in unauthorized read access to potentially sensitive data. This impacts both s3api deployments (Rocky or later), and swift3 deployments (Queens and earlier, no longer actively developed).
Scope: local
bookworm: resolved (fixed in 2.30.0-4)
bullseye: resolved (fixed in 2.26.0-10+deb11u1)
forky: resolved (fixed in 2.30.0-4)
sid: resolved (fixed in 2.30.0-4)
trixie: resolved (fixed in 2.30.0-4)
OSV
OpenStack Swift XML external entities (XXE) Injection
osv·2023-01-18
CVE-2022-47950 [MEDIUM] OpenStack Swift XML external entities (XXE) Injection
OpenStack Swift XML external entities (XXE) Injection
An issue was discovered in OpenStack Swift before 2.28.1, 2.29.x before 2.29.2, and 2.30.0. By supplying crafted XML files, an authenticated user may coerce the S3 API into returning arbitrary file contents from the host server, resulting in unauthorized read access to potentially sensitive data. This impacts both s3api deployments (Rocky or later), and swift3 deployments (Queens and earlier, no longer actively developed).
OSV
CVE-2022-47950: An issue was discovered in OpenStack Swift before 2
osv·2023-01-18·CVSS 6.5
CVE-2022-47950 [MEDIUM] CVE-2022-47950: An issue was discovered in OpenStack Swift before 2
An issue was discovered in OpenStack Swift before 2.28.1, 2.29.x before 2.29.2, and 2.30.0. By supplying crafted XML files, an authenticated user may coerce the S3 API into returning arbitrary file contents from the host server, resulting in unauthorized read access to potentially sensitive data. This impacts both s3api deployments (Rocky or later), and swift3 deployments (Queens and earlier, no longer actively developed).
GHSA
OpenStack Swift XML external entities (XXE) Injection
ghsa·2023-01-18
CVE-2022-47950 [MEDIUM] CWE-552 OpenStack Swift XML external entities (XXE) Injection
OpenStack Swift XML external entities (XXE) Injection
An issue was discovered in OpenStack Swift before 2.28.1, 2.29.x before 2.29.2, and 2.30.0. By supplying crafted XML files, an authenticated user may coerce the S3 API into returning arbitrary file contents from the host server, resulting in unauthorized read access to potentially sensitive data. This impacts both s3api deployments (Rocky or later), and swift3 deployments (Queens and earlier, no longer actively developed).
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://launchpad.net/bugs/1998625https://lists.debian.org/debian-lts-announce/2023/01/msg00021.htmlhttps://security.openstack.org/ossa/OSSA-2023-001.htmlhttps://www.debian.org/security/2023/dsa-5327https://launchpad.net/bugs/1998625https://lists.debian.org/debian-lts-announce/2023/01/msg00021.htmlhttps://security.openstack.org/ossa/OSSA-2023-001.htmlhttps://www.debian.org/security/2023/dsa-5327
2023-01-18
Published