Improper Authorization in Ceph - CVE-2023-43040

 

Improper Authorization in Ceph - CVE-2023-43040

Published: October 17, 2023 / Updated: August 2, 2024


Vulnerability identifier: #VU82112
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-43040
CWE-ID: CWE-285
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote user to bypass implemented security restrictions.

The vulnerability exists due to improper authorization in radogw API gateway in Ceph when processing POST requests. A remote unprivileged user can write to any bucket(s) accessible by a given key if a POST form-data contains a key called "bucket" with a value matching the bucket's name used to sign the request.


Affected software

Ceph
IBM Fusion HCI
Debian Linux
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Ubuntu
openEuler
Red Hat Ceph Storage
ceph-common (Ubuntu package)
ceph-base (Ubuntu package)
ceph (Ubuntu package)
haproxy (Red Hat package)
cephadm-ansible (Red Hat package)
ceph-ansible (Red Hat package)
ceph-base
ceph-resource-agents
python3-rgw
python-ceph-compat
libcephfs-devel
ceph-debuginfo
python3-ceph-argparse
ceph-selinux
librados-devel
ceph-mon
ceph-radosgw
rbd-mirror
libradosstriper1
python-rados
librgw2
ceph-mds
rados-objclass-devel
python-cephfs
python3-rados
librbd-devel
ceph-mgr
ceph-test
libradosstriper-devel
python-rgw
librados2
ceph
rbd-nbd
python-rbd
python3-cephfs
rbd-fuse
ceph-fuse
python3-rbd
ceph-debugsource
ceph-osd
librgw-devel
libcephfs2
librbd1
ceph-common
ceph (Debian package)
OpenShift Data Foundation (formerly OpenShift Container Storage)
Storage Ceph

How to mitigate CVE-2023-43040

Install updates from vendor's website.

Ceph - addressed in versions 17.2.6, 16.2.10-248.el8cp, 16.2.10-248.el9cp, 17.2.6-148.el9cp
ceph-common (Ubuntu package) - addressed in versions Ubuntu Pro, 15.2.17-0ubuntu0.20.04.6, 17.2.6-0ubuntu0.22.04.3, 18.2.0-0ubuntu3.1
ceph-base (Ubuntu package) - addressed in versions Ubuntu Pro, 15.2.17-0ubuntu0.20.04.6, 17.2.6-0ubuntu0.22.04.3, 18.2.0-0ubuntu3.1
ceph (Ubuntu package) - addressed in versions Ubuntu Pro, 15.2.17-0ubuntu0.20.04.6, 17.2.6-0ubuntu0.22.04.3, 18.2.0-0ubuntu3.1
haproxy (Red Hat package) - update to 2.2.19-5.el8cp
IBM Fusion HCI - update to 2.8.0
cephadm-ansible (Red Hat package) - update to 3.0.0-1.el9cp
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.14.0
ceph-ansible (Red Hat package) - update to 6.0.28.7-1.el8cp
Storage Ceph - update to 6.1z2
ceph-base - update to 12.2.8-23
ceph-resource-agents - update to 12.2.8-23
python3-rgw - update to 12.2.8-23
python-ceph-compat - update to 12.2.8-23
libcephfs-devel - update to 12.2.8-23
ceph-debuginfo - update to 12.2.8-23
python3-ceph-argparse - update to 12.2.8-23
ceph-selinux - update to 12.2.8-23
librados-devel - update to 12.2.8-23
ceph-mon - update to 12.2.8-23
ceph-radosgw - update to 12.2.8-23
rbd-mirror - update to 12.2.8-23
libradosstriper1 - update to 12.2.8-23
python-rados - update to 12.2.8-23
librgw2 - update to 12.2.8-23
ceph-mds - update to 12.2.8-23
rados-objclass-devel - update to 12.2.8-23
python-cephfs - update to 12.2.8-23
python3-rados - update to 12.2.8-23
librbd-devel - update to 12.2.8-23
ceph-mgr - update to 12.2.8-23
ceph-test - update to 12.2.8-23
libradosstriper-devel - update to 12.2.8-23
python-rgw - update to 12.2.8-23
librados2 - update to 12.2.8-23
ceph - update to 12.2.8-23
rbd-nbd - update to 12.2.8-23
python-rbd - update to 12.2.8-23
python3-cephfs - update to 12.2.8-23
rbd-fuse - update to 12.2.8-23
ceph-fuse - update to 12.2.8-23
python3-rbd - update to 12.2.8-23
ceph-debugsource - update to 12.2.8-23
ceph-osd - update to 12.2.8-23
librgw-devel - update to 12.2.8-23
libcephfs2 - update to 12.2.8-23
librbd1 - update to 12.2.8-23
ceph-common - update to 12.2.8-23
ceph (Debian package) - update to 16.2.15+ds-0+deb12u1

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins