Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-71191

Опубликовано: 28 июл. 2026
Источник: redhat
CVSS3: 8.2

Описание

In OpenStack Swift through 2.38.0, S3API middleware does not enforce that semantic x-amz-* headers are covered by the SigV4 signature on presigned URL requests. An attacker who obtains a presigned PUT URL can inject an unsigned X-Amz-Copy-Source header, causing Swift to perform a server-side copy from an arbitrary source object using the signer's authorization context. The attacker can read any object the signer has access to, provided the target project_id, container name, and object name are known. This affects all deployments using the default s3_acl=false configuration.

A flaw was found in the S3API middleware of OpenStack Swift. The SigV4 presigned URL implementation does not require that semantic x-amz-* headers be included in the request signature. An attacker who obtains a presigned PUT URL can inject unsigned headers such as X-Amz-Copy-Source to copy objects from the signer's storage, bypassing the intended scope of the presigned URL authorization. The attacker needs prior knowledge of the target project_id, container name, and object name.

Отчет

Red Hat OpenStack Platform (RHOSP) and Red Hat OpenStack Services on OpenShift (RHOSO) ship openstack-swift and are affected by this vulnerability. In default RHOSO deployments, the s3api filter is included in the active proxy-server pipeline, and the s3_acl option is not explicitly set (defaulting to false). SigV4 presigned URL requests are processed through the S3API middleware and are vulnerable. All RHOSP (13, 16.2, 17.1) and RHOSO (18.0) deployments with s3api enabled in the pipeline are affected.

Меры по смягчению последствий

If S3 API compatibility is not required, remove the s3api filter from the proxy-server pipeline in proxy-server.conf. This completely eliminates the attack surface. If S3 API is required, restrict the distribution and scope of presigned PUT URLs as an operational control, and apply the upstream patch when available. There is no configuration-only workaround that fully mitigates this issue while keeping S3 API functionality enabled.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenStack Platform 13 (Queens)rhosp13/openstack-swift-accountWill not fix
Red Hat OpenStack Platform 13 (Queens)rhosp13/openstack-swift-baseWill not fix
Red Hat OpenStack Platform 13 (Queens)rhosp13/openstack-swift-containerWill not fix
Red Hat OpenStack Platform 13 (Queens)rhosp13/openstack-swift-objectWill not fix
Red Hat OpenStack Platform 13 (Queens)rhosp13/openstack-swift-proxy-serverWill not fix
Red Hat OpenStack Platform 16.2openstack-swiftAffected
Red Hat OpenStack Platform 16.2rhosp-rhel8/openstack-swift-accountAffected
Red Hat OpenStack Platform 16.2rhosp-rhel8/openstack-swift-baseAffected
Red Hat OpenStack Platform 16.2rhosp-rhel8/openstack-swift-containerAffected
Red Hat OpenStack Platform 16.2rhosp-rhel8/openstack-swift-objectAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-863
https://bugzilla.redhat.com/show_bug.cgi?id=2503670openstack-swift: openstack-swift: S3API presigned URL unsigned header authorization bypass

8.2 High

CVSS3

Связанные уязвимости

ubuntu
26 дней назад

In OpenStack Swift through 2.38.0, S3API middleware does not enforce that semantic x-amz-* headers are covered by the SigV4 signature on presigned URL requests. An attacker who obtains a presigned PUT URL can inject an unsigned X-Amz-Copy-Source header, causing Swift to perform a server-side copy from an arbitrary source object using the signer's authorization context. The attacker can read any object the signer has access to, provided the target project_id, container name, and object name are known. This affects all deployments using the default s3_acl=false configuration.

nvd
26 дней назад

In OpenStack Swift through 2.38.0, S3API middleware does not enforce that semantic x-amz-* headers are covered by the SigV4 signature on presigned URL requests. An attacker who obtains a presigned PUT URL can inject an unsigned X-Amz-Copy-Source header, causing Swift to perform a server-side copy from an arbitrary source object using the signer's authorization context. The attacker can read any object the signer has access to, provided the target project_id, container name, and object name are known. This affects all deployments using the default s3_acl=false configuration.

debian
26 дней назад

In OpenStack Swift through 2.38.0, S3API middleware does not enforce t ...

github
26 дней назад

In OpenStack Swift through 2.38.0, S3API middleware does not enforce that semantic x-amz-* headers are covered by the SigV4 signature on presigned URL requests. An attacker who obtains a presigned PUT URL can inject an unsigned X-Amz-Copy-Source header, causing Swift to perform a server-side copy from an arbitrary source object using the signer's authorization context. The attacker can read any object the signer has access to, provided the target project_id, container name, and object name are known. This affects all deployments using the default s3_acl=false configuration.

8.2 High

CVSS3