Improper authentication in Ceph - CVE-2024-48916

 

Improper authentication in Ceph - CVE-2024-48916

Published: January 6, 2025


Vulnerability identifier: #VU102357
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-48916
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to an error when processing authentication requests within the WebTokenEngine::validate_signature() function in src/rgw/rgw_rest_sts.cc. A remote attacker can bypass authentication process and gain unauthorized access to the application.


Affected software

Ceph
Storage Ceph
openEuler
Ubuntu
oath-toolkit (Red Hat package)
librgw-devel
librgw2
cephfs-top
python3-ceph-argparse
python3-ceph-common
python3-cephfs
python3-rados
python3-rbd
python3-rgw
rados-objclass-devel
rbd-fuse
rbd-mirror
rbd-nbd
ceph-grafana-dashboards
ceph-mgr-cephadm
ceph-mgr-dashboard
ceph-mgr-diskprediction-local
ceph-mgr-k8sevents
ceph-mgr-modules-core
ceph-mgr-rook
ceph-prometheus-alerts
cephadm
ceph-selinux
ceph
ceph-base
ceph-common
ceph-debuginfo
ceph-debugsource
ceph-fuse
ceph-immutable-object-cache
ceph-mds
ceph-mgr
ceph-mon
ceph-osd
ceph-radosgw
ceph-resource-agents
librbd1
ceph-test
cephfs-mirror
libcephfs-devel
libcephfs2
libcephsqlite
libcephsqlite-devel
librados-devel
librados2
libradospp-devel
libradosstriper-devel
libradosstriper1
librbd-devel
ceph (Red Hat package)
ceph (Ubuntu package)
ceph-base (Ubuntu package)
radosgw (Ubuntu package)
ceph-common (Ubuntu package)
ceph-mib
ceph-volume
ceph-exporter
OpenShift Data Foundation (formerly OpenShift Container Storage)
Red Hat Ceph Storage

How to mitigate CVE-2024-48916

Install updates from vendor's website.

Ceph - update to 19.2.0-55.el9cp
Storage Ceph - update to 7.1z4
oath-toolkit (Red Hat package) - addressed in versions 2.6.12-1.el8cp, 2.6.12-1.el9cp
OpenShift Data Foundation (formerly OpenShift Container Storage) - addressed in versions 4, 4.14.18, 4.15.14
Red Hat Ceph Storage - addressed in versions 6.1, 7.1, 8.0
librgw-devel - addressed in versions 16.2.7-22, 18.2.2-6
librgw2 - addressed in versions 16.2.7-22, 18.2.2-6
cephfs-top - addressed in versions 16.2.7-22, 18.2.2-6
python3-ceph-argparse - addressed in versions 16.2.7-22, 18.2.2-6
python3-ceph-common - addressed in versions 16.2.7-22, 18.2.2-6
python3-cephfs - addressed in versions 16.2.7-22, 18.2.2-6
python3-rados - addressed in versions 16.2.7-22, 18.2.2-6
python3-rbd - addressed in versions 16.2.7-22, 18.2.2-6
python3-rgw - addressed in versions 16.2.7-22, 18.2.2-6
rados-objclass-devel - addressed in versions 16.2.7-22, 18.2.2-6
rbd-fuse - addressed in versions 16.2.7-22, 18.2.2-6
rbd-mirror - addressed in versions 16.2.7-22, 18.2.2-6
rbd-nbd - addressed in versions 16.2.7-22, 18.2.2-6
ceph-grafana-dashboards - addressed in versions 16.2.7-22, 18.2.2-6
ceph-mgr-cephadm - addressed in versions 16.2.7-22, 18.2.2-6
ceph-mgr-dashboard - addressed in versions 16.2.7-22, 18.2.2-6
ceph-mgr-diskprediction-local - addressed in versions 16.2.7-22, 18.2.2-6
ceph-mgr-k8sevents - addressed in versions 16.2.7-22, 18.2.2-6
ceph-mgr-modules-core - addressed in versions 16.2.7-22, 18.2.2-6
ceph-mgr-rook - addressed in versions 16.2.7-22, 18.2.2-6
ceph-prometheus-alerts - addressed in versions 16.2.7-22, 18.2.2-6
cephadm - addressed in versions 16.2.7-22, 18.2.2-6
ceph-selinux - addressed in versions 16.2.7-22, 18.2.2-6
ceph - addressed in versions 16.2.7-22, 18.2.2-6
ceph-base - addressed in versions 16.2.7-22, 18.2.2-6
ceph-common - addressed in versions 16.2.7-22, 18.2.2-6
ceph-debuginfo - addressed in versions 16.2.7-22, 18.2.2-6
ceph-debugsource - addressed in versions 16.2.7-22, 18.2.2-6
ceph-fuse - addressed in versions 16.2.7-22, 18.2.2-6
ceph-immutable-object-cache - addressed in versions 16.2.7-22, 18.2.2-6
ceph-mds - addressed in versions 16.2.7-22, 18.2.2-6
ceph-mgr - addressed in versions 16.2.7-22, 18.2.2-6
ceph-mon - addressed in versions 16.2.7-22, 18.2.2-6
ceph-osd - addressed in versions 16.2.7-22, 18.2.2-6
ceph-radosgw - addressed in versions 16.2.7-22, 18.2.2-6
ceph-resource-agents - addressed in versions 16.2.7-22, 18.2.2-6
librbd1 - addressed in versions 16.2.7-22, 18.2.2-6
ceph-test - addressed in versions 16.2.7-22, 18.2.2-6
cephfs-mirror - addressed in versions 16.2.7-22, 18.2.2-6
libcephfs-devel - addressed in versions 16.2.7-22, 18.2.2-6
libcephfs2 - addressed in versions 16.2.7-22, 18.2.2-6
libcephsqlite - addressed in versions 16.2.7-22, 18.2.2-6
libcephsqlite-devel - addressed in versions 16.2.7-22, 18.2.2-6
librados-devel - addressed in versions 16.2.7-22, 18.2.2-6
librados2 - addressed in versions 16.2.7-22, 18.2.2-6
libradospp-devel - addressed in versions 16.2.7-22, 18.2.2-6
libradosstriper-devel - addressed in versions 16.2.7-22, 18.2.2-6
libradosstriper1 - addressed in versions 16.2.7-22, 18.2.2-6
librbd-devel - addressed in versions 16.2.7-22, 18.2.2-6
ceph (Red Hat package) - addressed in versions 17.2.6-277.el8cp, 17.2.6-277.el9cp, 18.2.1-329.el8cp, 18.2.1-329.el9cp
ceph (Ubuntu package) - addressed in versions 17.2.7-0ubuntu0.22.04.2, 19.2.0-0ubuntu0.24.04.2, 19.2.0-0ubuntu2.1
ceph-base (Ubuntu package) - addressed in versions 17.2.7-0ubuntu0.22.04.2, 19.2.0-0ubuntu0.24.04.2, 19.2.0-0ubuntu2.1
radosgw (Ubuntu package) - addressed in versions 17.2.7-0ubuntu0.22.04.2, 19.2.0-0ubuntu0.24.04.2, 19.2.0-0ubuntu2.1
ceph-common (Ubuntu package) - addressed in versions 17.2.7-0ubuntu0.22.04.2, 19.2.0-0ubuntu0.24.04.2, 19.2.0-0ubuntu2.1
ceph-mib - update to 18.2.2-6
ceph-volume - update to 18.2.2-6
ceph-exporter - update to 18.2.2-6

External References

Related Security Bulletins