CVE-2022-47950 is a critical vulnerability affecting OpenStack Swift versions before 2.28.1, 2.29.x before 2.29.2, and 2.30.0. An authenticated attacker can exploit a flaw in the S3 API by supplying crafted XML files, leading to unauthorized read access of arbitrary file contents from the host server. This impacts both s3api and swift3 deployments, potentially exposing sensitive data. The vulnerability has a CVSS score of 6.5 (Medium), indicating a network-based attack with low complexity and requiring low privileges, resulting in high confidentiality impact. While the EPSS score is low, suggesting a low probability of exploitation in the wild, the FAUCET Risk Score of 37/100 indicates a moderate overall risk. Currently, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. The vulnerability has received minimal community discussion and media coverage, which is typical for a large percentage of CVEs.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.28.1CPE matchmatch criteria | cpe:2.3:a:openstack:swift:*:*:*:*:*:*:*:* | ||
>= 2.29.0, < 2.29.2CPE matchmatch criteria | cpe:2.3:a:openstack:swift:*:*:*:*:*:*:*:* | ||
2.30.0CPE matchmatch criteria | cpe:2.3:a:openstack:swift:2.30.0:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.