CVE-2022-47950 - CVE House
Back to Database
Status published Unknown CVE-2022-47950

An issue was discovered in OpenStack Swift before 2.28.1, 2.29.x...

Vulnerability Description

An issue was discovered in OpenStack Swift before 2.28.1, 2.29.x before 2.29.2, and 2.30.0. By supplying crafted XML files, an authenticated user may coerce the S3 API into returning arbitrary file contents from the host server, resulting in unauthorized read access to potentially sensitive data. This impacts both s3api deployments (Rocky or later), and swift3 deployments (Queens and earlier, no longer actively developed).

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-47950

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

swift, debian linux
Vulnerable Versions:
0, 2.29.0, 2.30.0, 10.0

Timeline

Official Publish: January 18th, 2023
Last Modified: April 4th, 2025
Added to House: July 21st, 2026

CVSS Vectors

No vector data available

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.