Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2022-47950
Description:An issue was discovered in OpenStack Swift before 2.28.1, 2.29.x before 2.29.2, and 2.30.0. By supplying crafted XML files, an authenticated user may coerce the S3 API into returning arbitrary file contents from the host server, resulting in unauthorized read access to potentially sensitive data. This impacts both s3api deployments (Rocky or later), and swift3 deployments (Queens and earlier, no longer actively developed).
Test IDs: 1.3.6.1.4.1.25623.1.0.893281   1.3.6.1.4.1.25623.1.1.12.2023.5852.1   1.3.6.1.4.1.25623.1.0.705327  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2022-47950
Debian Security Information: DSA-5327 (Google Search)
https://www.debian.org/security/2023/dsa-5327
https://launchpad.net/bugs/1998625
https://security.openstack.org/ossa/OSSA-2023-001.html
https://lists.debian.org/debian-lts-announce/2023/01/msg00021.html




© 1998-2025 E-Soft Inc. All rights reserved.