Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-50221

Опубликовано: 23 июн. 2026
Источник: redhat
CVSS3: 6.4
EPSS Низкий

Описание

In OpenStack Swift before 2.37.2, proxy-server does not strip internal update headers (X-Container-Host, X-Container-Device, X-Delete-At-Host, X-Delete-At-Device) from client requests before forwarding them to object-servers. An authenticated user with write access can inject these headers to redirect container update requests to an attacker-controlled server, enabling server-side request forgery. The SSRF requests expose internal cluster metadata including storage policy indexes, partition mappings, device names, and when at rest encryption is enabled, cipher text and initialization vectors for the container-level encryption key. The attacker can also cause "ghost listings" in arbitrary containers via the shard-range redirect mechanism.

A flaw was found in OpenStack Swift's proxy-server. Internal container update routing headers (X-Container-Host, X-Container-Device, X-Delete-At-Host, X-Delete-At-Device) are not stripped from client requests before being forwarded to object-servers. An authenticated user with write access can inject these headers to redirect internal container update requests to an attacker-controlled server, resulting in server-side request forgery. This can lead to disclosure of internal cluster metadata and, when at-rest encryption is enabled, exposure of encrypted container-level key material. Additionally, the attacker can create unauthorized listings in arbitrary containers via the shard-range redirect mechanism.

Отчет

Red Hat OpenStack Platform 13, 16.2, 17.1, and Red Hat OpenStack Services on OpenShift 18.0 ship OpenStack Swift proxy-server in affected versions and are vulnerable to this flaw. This vulnerability is rated as Moderate severity because exploitation requires an authenticated user with write access to at least one Swift container. The SSRF allows redirection of container update requests to attacker-controlled servers, exposing internal cluster metadata. When at-rest encryption is enabled, cipher text and initialization vectors for the container-level encryption key are also exposed, though the encryption key itself is not directly disclosed. The attack is network-accessible but requires valid credentials and write permissions, limiting the attacker population to existing tenants within the deployment.

Меры по смягчению последствий

There is no mitigation for this flaw. The only resolution is to upgrade OpenStack Swift to a patched version: 2.35.3 (for the 2.0.0+ series), 2.36.2 (for the 2.36.x series), or 2.37.2 (for the 2.37.x series). The risk is partially limited because exploitation requires an authenticated user with write access to at least one Swift container.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Developer Hubrhdh/rhdh-hub-rhel9Fix deferred
Red Hat OpenStack Platform 13 (Queens)rhosp13/openstack-swift-accountOut of support scope
Red Hat OpenStack Platform 13 (Queens)rhosp13/openstack-swift-baseOut of support scope
Red Hat OpenStack Platform 13 (Queens)rhosp13/openstack-swift-containerOut of support scope
Red Hat OpenStack Platform 13 (Queens)rhosp13/openstack-swift-objectOut of support scope
Red Hat OpenStack Platform 13 (Queens)rhosp13/openstack-swift-proxy-serverOut of support scope
Red Hat OpenStack Platform 16.2openstack-swiftFix deferred
Red Hat OpenStack Platform 16.2rhosp-rhel8/openstack-swift-accountFix deferred
Red Hat OpenStack Platform 16.2rhosp-rhel8/openstack-swift-baseFix deferred
Red Hat OpenStack Platform 16.2rhosp-rhel8/openstack-swift-containerFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-918
https://bugzilla.redhat.com/show_bug.cgi?id=2491876openstack-swift: OpenStack Swift: SSRF via internal update header injection in proxy-server

EPSS

Процентиль: 4%
0.00146
Низкий

6.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.4
ubuntu
около 1 месяца назад

In OpenStack Swift before 2.37.2, proxy-server does not strip internal update headers (X-Container-Host, X-Container-Device, X-Delete-At-Host, X-Delete-At-Device) from client requests before forwarding them to object-servers. An authenticated user with write access can inject these headers to redirect container update requests to an attacker-controlled server, enabling server-side request forgery. The SSRF requests expose internal cluster metadata including storage policy indexes, partition mappings, device names, and when at rest encryption is enabled, cipher text and initialization vectors for the container-level encryption key. The attacker can also cause "ghost listings" in arbitrary containers via the shard-range redirect mechanism.

CVSS3: 5.4
nvd
около 1 месяца назад

In OpenStack Swift before 2.37.2, proxy-server does not strip internal update headers (X-Container-Host, X-Container-Device, X-Delete-At-Host, X-Delete-At-Device) from client requests before forwarding them to object-servers. An authenticated user with write access can inject these headers to redirect container update requests to an attacker-controlled server, enabling server-side request forgery. The SSRF requests expose internal cluster metadata including storage policy indexes, partition mappings, device names, and when at rest encryption is enabled, cipher text and initialization vectors for the container-level encryption key. The attacker can also cause "ghost listings" in arbitrary containers via the shard-range redirect mechanism.

CVSS3: 5.4
debian
около 1 месяца назад

In OpenStack Swift before 2.37.2, proxy-server does not strip internal ...

CVSS3: 5.4
github
около 1 месяца назад

In OpenStack Swift before 2.37.2, proxy-server does not strip internal update headers (X-Container-Host, X-Container-Device, X-Delete-At-Host, X-Delete-At-Device) from client requests before forwarding them to object-servers. An authenticated user with write access can inject these headers to redirect container update requests to an attacker-controlled server, enabling server-side request forgery. The SSRF requests expose internal cluster metadata including storage policy indexes, partition mappings, device names, and when at rest encryption is enabled, cipher text and initialization vectors for the container-level encryption key. The attacker can also cause "ghost listings" in arbitrary containers via the shard-range redirect mechanism.

EPSS

Процентиль: 4%
0.00146
Низкий

6.4 Medium

CVSS3