漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
N/A
Vulnerability Description
In OpenStack Swift before 2.37.2, proxy-server does not strip internal update headers (X-Container-Host, X-Container-Device, X-Delete-At-Host, X-Delete-At-Device) from client requests before forwarding them to object-servers. An authenticated user with write access can inject these headers to redirect container update requests to an attacker-controlled server, enabling server-side request forgery. The SSRF requests expose internal cluster metadata including storage policy indexes, partition mappings, device names, and when at rest encryption is enabled, cipher text and initialization vectors for the container-level encryption key. The attacker can also cause "ghost listings" in arbitrary containers via the shard-range redirect mechanism.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:N
Vulnerability Type
服务端请求伪造(SSRF)
Vulnerability Title
OpenStack swift 服务端请求伪造漏洞
Vulnerability Description
OpenStack Swift是OpenStack基金会开源的一个存储永久静态数据的存储项目。 OpenStack Swift 2.0.0版本至2.35.3之前版本、2.36.0版本至2.36.2之前版本和2.37.0版本至2.37.2之前版本存在服务端请求伪造漏洞,该漏洞源于proxy-server未清除内部更新标头,可能导致已认证用户通过注入标头重定向容器更新请求,实现服务端请求伪造,暴露内部集群元数据,并可能导致任意容器中的“幽灵列表”。
CVSS Information
N/A
Vulnerability Type
N/A