Vulnerability record · CVE-2022-47950 · published 18 January 2023
CVE-2022-47950: Openstack swift vulnerability
Openstack · Swift
An issue was discovered in OpenStack Swift before 2.28.1, 2.29.x before 2.29.2, and 2.30.0. By supplying crafted XML files, an authenticated user may coerce the S3 API into returning arbitrary file contents from the host server, resulting in unauthorized read access to potentially sensitive data. This impacts both s3api deployments (Rocky or later), and swift3 deployments (Queens and earlier, no longer actively developed).
Description
An issue was discovered in OpenStack Swift before 2.28.1, 2.29.x before 2.29.2, and 2.30.0. By supplying crafted XML files, an authenticated user may coerce the S3 API into returning arbitrary file contents from the host server, resulting in unauthorized read access to potentially sensitive data. This impacts both s3api deployments (Rocky or later), and swift3 deployments (Queens and earlier, no longer actively developed).
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://launchpad.net/bugs/1998625 | ExploitIssue TrackingPatchVendor Advisory |
| https://lists.debian.org/debian-lts-announce/2023/01/msg00021.html | Mailing ListThird Party Advisory |
| https://security.openstack.org/ossa/OSSA-2023-001.html | PatchVendor Advisory |
| https://www.debian.org/security/2023/dsa-5327 | |
| https://launchpad.net/bugs/1998625 | ExploitIssue TrackingPatchVendor Advisory |
| https://lists.debian.org/debian-lts-announce/2023/01/msg00021.html | Mailing ListThird Party Advisory |
| https://security.openstack.org/ossa/OSSA-2023-001.html | PatchVendor Advisory |
| https://www.debian.org/security/2023/dsa-5327 |
Track CVE-2022-47950 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-47950), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.