openstack-swift: Arbitrary file access through custom S3 XML entities
Published Jan 18, 2023
7.7
HIGHCVSS 3.1
EPSS 1.01%
Description
An issue was discovered in OpenStack Swift before 2.28.1, 2.29.x before 2.29.2, and 2.30.0. By supplying crafted XML files, an authenticated user may coerce the S3 API into returning arbitrary file contents from the host server, resulting in unauthorized read access to potentially sensitive data. This impacts both s3api deployments (Rocky or later), and swift3 deployments (Queens and earlier, no longer actively developed).
Affected products
No data.
No data.
Red Hat OpenStack Platform 13.0 (Queens) for RHEL 7.6 EUS
openstack-swift-plugin-swift3-0:1.12.1-1.el7ost
Fixed · RHSA-2023:1277
Red Hat OpenStack Platform 13.0 - ELS
openstack-swift-plugin-swift3-0:1.12.1-1.el7ost
Fixed · RHSA-2023:1277
Red Hat OpenStack Platform 16.1
openstack-swift-0:2.23.2-1.20230201163512.eef87ee.el8ost
Fixed · RHSA-2023:1277
Red Hat OpenStack Platform 16.2
openstack-swift-0:2.23.4-2.20220422185313.2829195.el8ost
Fixed · RHSA-2023:1277
Red Hat OpenStack Platform 17.0
openstack-swift-0:2.27.1-0.20230201120900.6a1a8ce.el9ost
Fixed · RHSA-2023:1013
Red Hat Storage 3
openstack-swift
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenStack Platform 13.0 (Queens) for RHEL 7.6 EUS | openstack-swift-plugin-swift3-0:1.12.1-1.el7ost | Fixed | RHSA-2023:1277 |
| Red Hat OpenStack Platform 13.0 - ELS | openstack-swift-plugin-swift3-0:1.12.1-1.el7ost | Fixed | RHSA-2023:1277 |
| Red Hat OpenStack Platform 16.1 | openstack-swift-0:2.23.2-1.20230201163512.eef87ee.el8ost | Fixed | RHSA-2023:1277 |
| Red Hat OpenStack Platform 16.2 | openstack-swift-0:2.23.4-2.20220422185313.2829195.el8ost | Fixed | RHSA-2023:1277 |
| Red Hat OpenStack Platform 17.0 | openstack-swift-0:2.27.1-0.20230201120900.6a1a8ce.el9ost | Fixed | RHSA-2023:1013 |
| Red Hat Storage 3 | openstack-swift | Affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (17)
- https://access.redhat.com/security/cve/CVE-2022-47950 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2160618 Issue Tracking
- https://github.com/advisories/GHSA-274c-rx2j-2v3x Advisory
- https://github.com/openstack/swift/commit/12e54391861e7d182d58f89fb88b027e65842640
- https://github.com/openstack/swift/commit/7d13d1a82e1f5d01205a13184907501b4fcbe2b0
- https://github.com/openstack/swift/commit/8dd96470a859dc7b189404fb67bd3899ae9c617f
- https://github.com/openstack/swift/commit/b8467e190f6fc67fd8fb6a8c5e32b2aa6a10fd8e
- https://github.com/openstack/swift/commit/baa98848451b5c234443a068691e12841a5a8383
- https://github.com/openstack/swift/commit/c834e7a53d5a33a3fd13ffd954e6f4f4ee953dfc
- https://github.com/openstack/swift/commit/d8d04ef43c90079d436b2e49617b4425ba39c28e
- https://github.com/openstack/swift/commit/f10672514217adadfc776d9ea2ffb20a37ce073b
- https://launchpad.net/bugs/1998625 ExploitIssue TrackingPatchVendor Advisory
- https://lists.debian.org/debian-lts-announce/2023/01/msg00021.html mailing-listMailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-47950
- https://security.openstack.org/ossa/OSSA-2023-001.html PatchVendor Advisory
- https://www.cve.org/CVERecord?id=CVE-2022-47950
- https://www.debian.org/security/2023/dsa-5327 vendor-advisory
Change history (0)
No recorded changes yet.