Jan. 18, 2023, 5:15 p.m. |

National Vulnerability Database web.nvd.nist.gov

An issue was discovered in OpenStack Swift before 2.28.1, 2.29.x before 2.29.2, and 2.30.0. By supplying crafted XML files, an authenticated user may coerce the S3 API into returning arbitrary file contents from the host server, resulting in unauthorized read access to potentially sensitive data. This impacts both s3api deployments (Rocky or later), and swift3 deployments (Queens and earlier, no longer actively developed).

access api coerce cve data file files host issue may sensitive data server swift xml

SOC 2 Manager, Audit and Certification

@ Deloitte | US and CA Multiple Locations

Information Security Engineers

@ D. E. Shaw Research | New York City

Network Security Engineer

@ Ørsted | Kuala Lumpur, MY

Senior Director of Foundation Relations, Johns Hopkins University & Medicine

@ Johns Hopkins University | Baltimore, MD, United States, 21209

Global Cybersecurity Head

@ CMA CGM | Marseille, FR

Cyber Security Analyst

@ QinetiQ US | Reston, VA, United States