CVE-2022-47950
Discription

An issue was discovered in OpenStack Swift before 2.28.1, 2.29.x before
2.29.2, and 2.30.0. By supplying crafted XML files, an authenticated user
may coerce the S3 API into returning arbitrary file contents from the host
server, resulting in unauthorized read access to potentially sensitive
data. This impacts both s3api deployments (Rocky or later), and swift3
deployments (Queens and earlier, no longer actively developed).Read More

Back to Main

Subscribe for the latest news: