Executive brief
OpenStack Swift is an object storage service that provides S3-compatible APIs. An XML external entity (XXE) injection vulnerability in the S3 API allows authenticated users to read arbitrary files from the server, potentially exposing sensitive data such as credentials and secrets stored on the host system.
Technical details
OpenStack Swift versions before 2.28.1, 2.29.x before 2.29.2, and 2.30.0 fail to disable XML external entity (XXE) resolution in the S3 API middleware. An authenticated attacker can supply crafted XML in S3 API requests to trigger entity resolution, allowing arbitrary file read from the server's filesystem. The vulnerability affects both s3api (Rocky and later) and swift3 (Queens and earlier) deployments. The fix disables entity resolution, replacing unknown entities with empty strings. Patches are available in versions 2.28.1, 2.29.2, and 2.30.1 and later.
Affected products
- OpenStack Swift before 2.28.1, 2.29.0–2.29.1, 2.30.0
Timeline
- 2023-01-18: disclosed
- 2023-01-18: patched: Patches released for versions 2.28.1, 2.29.2, and 2.30.1