[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250053

 
 

909

 
 

195940

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS2-2023-2297 --- ceph-common

ID: oval:org.secpod.oval:def:1701873Date: (C)2023-11-24   (M)2024-02-26
Class: PATCHFamily: unix




A flaw was found in rgw. This flaw allows an unprivileged user to write to any bucket accessible by a given key if a POST's form-data contains a key called 'bucket' with a value matching the bucket's name used to sign the request. This issue results in a user being able to upload to any bucket accessible by the specified access key as long as the bucket in the POST policy matches the bucket in the said POST form part

Platform:
Amazon Linux 2
Product:
ceph-common
librados2
python-rados
librbd1
python-rbd
Reference:
ALAS2-2023-2297
CVE-2023-43040
CVE    1
CVE-2023-43040
CPE    3
cpe:/o:amazon:linux:2
cpe:/a:ceph:librbd1
cpe:/a:librados2:librados2

© SecPod Technologies