RADOS Gateway in Ceph 12.1.0 through 12.2.1 allows remote authenticated users to cause a denial of service (assertion failure and application exit) by leveraging "full" (not necessarily admin) privileges to post an invalid profile to the admin API, related to rgw/rgw_iam_policy.cc, rgw/rgw_basic_types.h, and rgw/rgw_iam_types.h.
CVSS Details
- CVSS 3.0 Base Score: 6.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Suse | — | Upgrade librados-develUpgrade rbd-nbdUpgrade python-rgwUpgrade python-rbdUpgrade librbd1Upgrade libradosstriper-develUpgrade python3-rbdUpgrade python-cephfsUpgrade rados-objclass-develUpgrade ceph-commonUpgrade libcephfs-develUpgrade python3-cephfsUpgrade python3-ceph-argparseUpgrade libradospp-develUpgrade python3-radosUpgrade libcephfs2Upgrade python3-rgwUpgrade libradosstriper1Upgrade python3-ceph-commonUpgrade librbd-develUpgrade librados2Upgrade librgw-develUpgrade librgw2Upgrade python-rados | May 19, 2018 | Dec 20, 2017 |
| Ubuntu | — | Upgrade ceph | Nov 19, 2024 | Dec 20, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub