Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-47950

23
FAUCET Score

CVE-2022-47950 is a critical vulnerability affecting OpenStack Swift versions before 2.28.1, 2.29.x before 2.29.2, and 2.30.0. An authenticated attacker can exploit a flaw in the S3 API by supplying crafted XML files, leading to unauthorized read access of arbitrary file contents from the host server. This impacts both s3api and swift3 deployments, potentially exposing sensitive data. The vulnerability has a CVSS score of 6.5 (Medium), indicating a network-based attack with low complexity and requiring low privileges, resulting in high confidentiality impact. While the EPSS score is low, suggesting a low probability of exploitation in the wild, the FAUCET Risk Score of 37/100 indicates a moderate overall risk. Currently, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. The vulnerability has received minimal community discussion and media coverage, which is typical for a large percentage of CVEs.

Impacted Technologies

VendorProductVersion(s)CPE
< 2.28.1CPE matchmatch criteria
cpe:2.3:a:openstack:swift:*:*:*:*:*:*:*:*
>= 2.29.0, < 2.29.2CPE matchmatch criteria
cpe:2.3:a:openstack:swift:*:*:*:*:*:*:*:*
2.30.0CPE matchmatch criteria
cpe:2.3:a:openstack:swift:2.30.0:*:*:*:*:*:*:*
10.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

6.5MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
2.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.00%
Probability of exploitation in next 30 days
EPSS Percentile
59.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-24
Model: v2026.06.15
This CVE's current EPSS score of 0.0100 is in the 72nd percentile among its peer group of 21,939 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (10)

pippatch availablevia ghsa
Product: swiftFixed in: 2.28.1
pippatch availablevia ghsa
Product: swiftFixed in: 2.29.2
pippatch availablevia ghsa
Product: swiftFixed in: 2.30.1
redhatpatch availablevia redhat_api
Product: Red Hat OpenStack Platform 13.0 (Queens) for RHEL 7.6 EUSFixed in: openstack-swift-plugin-swift3-0:1.12.1-1.el7ost
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenStack Platform 13.0 - ELSFixed in: openstack-swift-plugin-swift3-0:1.12.1-1.el7ost
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenStack Platform 16.2Fixed in: openstack-swift-0:2.23.4-2.20220422185313.2829195.el8ost
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenStack Platform 17.0Fixed in: openstack-swift-0:2.27.1-0.20230201120900.6a1a8ce.el9ost
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenStack Platform 16.1Fixed in: openstack-swift-0:2.23.2-1.20230201163512.eef87ee.el8ost
View patch
ubuntupatch availablevia nvd_reference
View patch
redhatno patchvia redhat_api
Product: Red Hat Storage 3Fixed in: openstack-swift

Vendor Advisories (2)

pipGHSA-274c-rx2j-2v3xmedium

OpenStack Swift XML external entities (XXE) Injection

Jan 18, 2023
redhatCVE-2022-47950Important

openstack-swift: Arbitrary file access through custom S3 XML entities

Jan 17, 2023

References

launchpad.net / bugs/1998625
ExploitIssue TrackingPatchVendor Advisory
lists.debian.org / debian-lts-announce/2023/01/msg00021.html
Mailing ListThird Party Advisory
security.openstack.org / ossa/OSSA-2023-001.html
PatchVendor Advisory
debian.org / security/2023/dsa-5327