Описание
In OpenStack Swift through 2.38.0, S3API middleware does not enforce that semantic x-amz-* headers are covered by the SigV4 signature on presigned URL requests. An attacker who obtains a presigned PUT URL can inject an unsigned X-Amz-Copy-Source header, causing Swift to perform a server-side copy from an arbitrary source object using the signer's authorization context. The attacker can read any object the signer has access to, provided the target project_id, container name, and object name are known. This affects all deployments using the default s3_acl=false configuration.
A flaw was found in the S3API middleware of OpenStack Swift. The SigV4 presigned URL implementation does not require that semantic x-amz-* headers be included in the request signature. An attacker who obtains a presigned PUT URL can inject unsigned headers such as X-Amz-Copy-Source to copy objects from the signer's storage, bypassing the intended scope of the presigned URL authorization. The attacker needs prior knowledge of the target project_id, container name, and object name.
Отчет
Red Hat OpenStack Platform (RHOSP) and Red Hat OpenStack Services on OpenShift (RHOSO) ship openstack-swift and are affected by this vulnerability. In default RHOSO deployments, the s3api filter is included in the active proxy-server pipeline, and the s3_acl option is not explicitly set (defaulting to false). SigV4 presigned URL requests are processed through the S3API middleware and are vulnerable. All RHOSP (13, 16.2, 17.1) and RHOSO (18.0) deployments with s3api enabled in the pipeline are affected.
Меры по смягчению последствий
If S3 API compatibility is not required, remove the s3api filter from the proxy-server pipeline in proxy-server.conf. This completely eliminates the attack surface. If S3 API is required, restrict the distribution and scope of presigned PUT URLs as an operational control, and apply the upstream patch when available. There is no configuration-only workaround that fully mitigates this issue while keeping S3 API functionality enabled.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat OpenStack Platform 13 (Queens) | rhosp13/openstack-swift-account | Will not fix | ||
| Red Hat OpenStack Platform 13 (Queens) | rhosp13/openstack-swift-base | Will not fix | ||
| Red Hat OpenStack Platform 13 (Queens) | rhosp13/openstack-swift-container | Will not fix | ||
| Red Hat OpenStack Platform 13 (Queens) | rhosp13/openstack-swift-object | Will not fix | ||
| Red Hat OpenStack Platform 13 (Queens) | rhosp13/openstack-swift-proxy-server | Will not fix | ||
| Red Hat OpenStack Platform 16.2 | openstack-swift | Affected | ||
| Red Hat OpenStack Platform 16.2 | rhosp-rhel8/openstack-swift-account | Affected | ||
| Red Hat OpenStack Platform 16.2 | rhosp-rhel8/openstack-swift-base | Affected | ||
| Red Hat OpenStack Platform 16.2 | rhosp-rhel8/openstack-swift-container | Affected | ||
| Red Hat OpenStack Platform 16.2 | rhosp-rhel8/openstack-swift-object | Affected |
Показывать по
Дополнительная информация
Статус:
8.2 High
CVSS3
Связанные уязвимости
In OpenStack Swift through 2.38.0, S3API middleware does not enforce that semantic x-amz-* headers are covered by the SigV4 signature on presigned URL requests. An attacker who obtains a presigned PUT URL can inject an unsigned X-Amz-Copy-Source header, causing Swift to perform a server-side copy from an arbitrary source object using the signer's authorization context. The attacker can read any object the signer has access to, provided the target project_id, container name, and object name are known. This affects all deployments using the default s3_acl=false configuration.
In OpenStack Swift through 2.38.0, S3API middleware does not enforce that semantic x-amz-* headers are covered by the SigV4 signature on presigned URL requests. An attacker who obtains a presigned PUT URL can inject an unsigned X-Amz-Copy-Source header, causing Swift to perform a server-side copy from an arbitrary source object using the signer's authorization context. The attacker can read any object the signer has access to, provided the target project_id, container name, and object name are known. This affects all deployments using the default s3_acl=false configuration.
In OpenStack Swift through 2.38.0, S3API middleware does not enforce t ...
In OpenStack Swift through 2.38.0, S3API middleware does not enforce that semantic x-amz-* headers are covered by the SigV4 signature on presigned URL requests. An attacker who obtains a presigned PUT URL can inject an unsigned X-Amz-Copy-Source header, causing Swift to perform a server-side copy from an arbitrary source object using the signer's authorization context. The attacker can read any object the signer has access to, provided the target project_id, container name, and object name are known. This affects all deployments using the default s3_acl=false configuration.
8.2 High
CVSS3