Ceph 是一个开源的分布式存储平台,提供对象存储、块存储和文件存储。在 20.2.4 和 19.2.6 之前的版本中,RADOS 网关(RGW)使用 AES-128-CBC 处理器保护 STS 会话令牌,但该处理器不提供消息认证,这使得持有任一有效 STS 令牌的攻击者可以在未被检测到的情况下篡改令牌,并提升权限至完整的 RGW 管理访问权限。由于密文未经过认证,攻击者可以对令牌中的 、 和 字段执行 CBC 位翻转(bit-flip);若伪造的 值为真,将触发全局管理权限覆盖,从而绕过所有能力(capabili
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-50152 | 9.1 CRITICAL | Ceph Monitor subscription handler improperly authorizes config-key store reads, exposing c |
| CVE-2025-30156 | 8.9 HIGH | Ceph: AES-CBC misuse in CephX and RADOSGW enables authentication bypass and credential for |
| CVE-2026-54330 | 8.1 HIGH | Ceph RGW SigV4 handler accepts unsigned x-amz-* headers on presigned requests, allowing pr |
No comments yet