Improper authentication in Ceph - CVE-2024-48916
Published: January 6, 2025
Vulnerability details
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to an error when processing authentication requests within the WebTokenEngine::validate_signature() function in src/rgw/rgw_rest_sts.cc. A remote attacker can bypass authentication process and gain unauthorized access to the application.
Affected software
Storage Ceph
openEuler
Ubuntu
oath-toolkit (Red Hat package)
librgw-devel
librgw2
cephfs-top
python3-ceph-argparse
python3-ceph-common
python3-cephfs
python3-rados
python3-rbd
python3-rgw
rados-objclass-devel
rbd-fuse
rbd-mirror
rbd-nbd
ceph-grafana-dashboards
ceph-mgr-cephadm
ceph-mgr-dashboard
ceph-mgr-diskprediction-local
ceph-mgr-k8sevents
ceph-mgr-modules-core
ceph-mgr-rook
ceph-prometheus-alerts
cephadm
ceph-selinux
ceph
ceph-base
ceph-common
ceph-debuginfo
ceph-debugsource
ceph-fuse
ceph-immutable-object-cache
ceph-mds
ceph-mgr
ceph-mon
ceph-osd
ceph-radosgw
ceph-resource-agents
librbd1
ceph-test
cephfs-mirror
libcephfs-devel
libcephfs2
libcephsqlite
libcephsqlite-devel
librados-devel
librados2
libradospp-devel
libradosstriper-devel
libradosstriper1
librbd-devel
ceph (Red Hat package)
ceph (Ubuntu package)
ceph-base (Ubuntu package)
radosgw (Ubuntu package)
ceph-common (Ubuntu package)
ceph-mib
ceph-volume
ceph-exporter
OpenShift Data Foundation (formerly OpenShift Container Storage)
Red Hat Ceph Storage
How to mitigate CVE-2024-48916
Storage Ceph - update to 7.1z4
oath-toolkit (Red Hat package) - addressed in versions 2.6.12-1.el8cp, 2.6.12-1.el9cp
OpenShift Data Foundation (formerly OpenShift Container Storage) - addressed in versions 4, 4.14.18, 4.15.14
Red Hat Ceph Storage - addressed in versions 6.1, 7.1, 8.0
librgw-devel - addressed in versions 16.2.7-22, 18.2.2-6
librgw2 - addressed in versions 16.2.7-22, 18.2.2-6
cephfs-top - addressed in versions 16.2.7-22, 18.2.2-6
python3-ceph-argparse - addressed in versions 16.2.7-22, 18.2.2-6
python3-ceph-common - addressed in versions 16.2.7-22, 18.2.2-6
python3-cephfs - addressed in versions 16.2.7-22, 18.2.2-6
python3-rados - addressed in versions 16.2.7-22, 18.2.2-6
python3-rbd - addressed in versions 16.2.7-22, 18.2.2-6
python3-rgw - addressed in versions 16.2.7-22, 18.2.2-6
rados-objclass-devel - addressed in versions 16.2.7-22, 18.2.2-6
rbd-fuse - addressed in versions 16.2.7-22, 18.2.2-6
rbd-mirror - addressed in versions 16.2.7-22, 18.2.2-6
rbd-nbd - addressed in versions 16.2.7-22, 18.2.2-6
ceph-grafana-dashboards - addressed in versions 16.2.7-22, 18.2.2-6
ceph-mgr-cephadm - addressed in versions 16.2.7-22, 18.2.2-6
ceph-mgr-dashboard - addressed in versions 16.2.7-22, 18.2.2-6
ceph-mgr-diskprediction-local - addressed in versions 16.2.7-22, 18.2.2-6
ceph-mgr-k8sevents - addressed in versions 16.2.7-22, 18.2.2-6
ceph-mgr-modules-core - addressed in versions 16.2.7-22, 18.2.2-6
ceph-mgr-rook - addressed in versions 16.2.7-22, 18.2.2-6
ceph-prometheus-alerts - addressed in versions 16.2.7-22, 18.2.2-6
cephadm - addressed in versions 16.2.7-22, 18.2.2-6
ceph-selinux - addressed in versions 16.2.7-22, 18.2.2-6
ceph - addressed in versions 16.2.7-22, 18.2.2-6
ceph-base - addressed in versions 16.2.7-22, 18.2.2-6
ceph-common - addressed in versions 16.2.7-22, 18.2.2-6
ceph-debuginfo - addressed in versions 16.2.7-22, 18.2.2-6
ceph-debugsource - addressed in versions 16.2.7-22, 18.2.2-6
ceph-fuse - addressed in versions 16.2.7-22, 18.2.2-6
ceph-immutable-object-cache - addressed in versions 16.2.7-22, 18.2.2-6
ceph-mds - addressed in versions 16.2.7-22, 18.2.2-6
ceph-mgr - addressed in versions 16.2.7-22, 18.2.2-6
ceph-mon - addressed in versions 16.2.7-22, 18.2.2-6
ceph-osd - addressed in versions 16.2.7-22, 18.2.2-6
ceph-radosgw - addressed in versions 16.2.7-22, 18.2.2-6
ceph-resource-agents - addressed in versions 16.2.7-22, 18.2.2-6
librbd1 - addressed in versions 16.2.7-22, 18.2.2-6
ceph-test - addressed in versions 16.2.7-22, 18.2.2-6
cephfs-mirror - addressed in versions 16.2.7-22, 18.2.2-6
libcephfs-devel - addressed in versions 16.2.7-22, 18.2.2-6
libcephfs2 - addressed in versions 16.2.7-22, 18.2.2-6
libcephsqlite - addressed in versions 16.2.7-22, 18.2.2-6
libcephsqlite-devel - addressed in versions 16.2.7-22, 18.2.2-6
librados-devel - addressed in versions 16.2.7-22, 18.2.2-6
librados2 - addressed in versions 16.2.7-22, 18.2.2-6
libradospp-devel - addressed in versions 16.2.7-22, 18.2.2-6
libradosstriper-devel - addressed in versions 16.2.7-22, 18.2.2-6
libradosstriper1 - addressed in versions 16.2.7-22, 18.2.2-6
librbd-devel - addressed in versions 16.2.7-22, 18.2.2-6
ceph (Red Hat package) - addressed in versions 17.2.6-277.el8cp, 17.2.6-277.el9cp, 18.2.1-329.el8cp, 18.2.1-329.el9cp
ceph (Ubuntu package) - addressed in versions 17.2.7-0ubuntu0.22.04.2, 19.2.0-0ubuntu0.24.04.2, 19.2.0-0ubuntu2.1
ceph-base (Ubuntu package) - addressed in versions 17.2.7-0ubuntu0.22.04.2, 19.2.0-0ubuntu0.24.04.2, 19.2.0-0ubuntu2.1
radosgw (Ubuntu package) - addressed in versions 17.2.7-0ubuntu0.22.04.2, 19.2.0-0ubuntu0.24.04.2, 19.2.0-0ubuntu2.1
ceph-common (Ubuntu package) - addressed in versions 17.2.7-0ubuntu0.22.04.2, 19.2.0-0ubuntu0.24.04.2, 19.2.0-0ubuntu2.1
ceph-mib - update to 18.2.2-6
ceph-volume - update to 18.2.2-6
ceph-exporter - update to 18.2.2-6
External References
Related Security Bulletins
- Improper authentication in Ceph
- Ubuntu update for ceph
- Improper authentication in Red Hat Ceph Storage 8
- Improper authentication in Red Hat Ceph Storage 8
- openEuler 22.03 LTS SP3 update for ceph
- openEuler 24.03 LTS SP1 update for ceph
- openEuler 24.03 LTS update for ceph
- openEuler 22.03 LTS SP4 update for ceph
- Multiple vulnerabilities in Red Hat Ceph Storage 6
- Multiple vulnerabilities in Red Hat Ceph Storage 7
- Multiple vulnerabilities in OpenShift Data Foundation (formerly OpenShift Container Storage)
- Multiple vulnerabilities in OpenShift Data Foundation (formerly OpenShift Container Storage) 4.15
- Multiple vulnerabilities in OpenShift Data Foundation (formerly OpenShift Container Storage) 4.14
- IBM Storage Ceph update for Ceph Rados Gateway (RadosGW)