PT-2023-1506 · Openstack+2 · Openstack Swift+2

Sebastien Meriot

·

Published

2023-01-18

·

Updated

2023-06-05

·

CVE-2022-47950

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenStack Swift versions prior to 2.28.1 OpenStack Swift versions 2.29.x prior to 2.29.2 OpenStack Swift version 2.30.0
Description The issue is related to the S3 API interface of the OpenStack Swift distributed object storage system. It allows an authenticated user to coerce the S3 API into returning arbitrary file contents from the host server by supplying crafted XML files. This results in unauthorized read access to potentially sensitive data. The issue affects both s3api deployments (Rocky or later) and swift3 deployments (Queens and earlier).
Recommendations For OpenStack Swift versions prior to 2.28.1, update to version 2.28.1 or later. For OpenStack Swift versions 2.29.x prior to 2.29.2, update to version 2.29.2 or later. For OpenStack Swift version 2.30.0, update to a version later than 2.30.0. As a temporary workaround, consider restricting access to the S3 API to minimize the risk of exploitation.

Exploit

Fix

Files Accessible to External Parties

Information Disclosure

XXE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-00933
CVE-2022-47950
DLA-3281-1
DSA-5327-1
GHSA-274C-RX2J-2V3X
RHSA-2023:1013
RHSA-2023:1277
SUSE-SU-2023:0323-1
SUSE-SU-2023:2378-1
USN-5852-1

Affected Products

Linuxmint
Openstack Swift
Ubuntu