PT-2026-82771 · Ceph · Ceph
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Ceph versions prior to 20.2.4
Ceph versions prior to 19.2.6
Description
The Ceph Object Gateway (RGW) SigV4 handler fails to reject requests containing
x-amz-* headers that are not included in the signed header set. While AWS S3 requires all x-amz-* headers in a SigV4 request to be signed, RGW only validates headers listed in X-Amz-SignedHeaders and ignores additional unsigned ones, allowing them to take effect. An attacker with a presigned PUT URL can attach arbitrary unsigned x-amz-* headers to escalate privileges and gain capabilities beyond what the signer intended.Recommendations
Update to version 20.2.4 or later.
Update to version 19.2.6 or later.
Exploit
Fix
Improper Verification of Cryptographic Signature
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ceph