漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
N/A
Vulnerability Description
In OpenStack Swift through 2.38.0, S3API middleware does not enforce that semantic x-amz-* headers are covered by the SigV4 signature on presigned URL requests. An attacker who obtains a presigned PUT URL can inject an unsigned X-Amz-Copy-Source header, causing Swift to perform a server-side copy from an arbitrary source object using the signer's authorization context. The attacker can read any object the signer has access to, provided the target project_id, container name, and object name are known. This affects all deployments using the default s3_acl=false configuration.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Vulnerability Type
授权机制不正确
Vulnerability Title
OpenStack Swift 授权问题漏洞
Vulnerability Description
OpenStack Swift是OpenStack基金会开源的一个存储永久静态数据的存储项目。 OpenStack Swift 2.38.0及之前版本存在授权问题漏洞,该漏洞源于S3API中间件未强制要求预签名URL请求中的语义x-amz-*标头由SigV4签名覆盖,可能导致攻击者注入未签名的X-Amz-Copy-Source标头,利用签名者的授权上下文读取任意对象。
CVSS Information
N/A
Vulnerability Type
N/A