Ceph 是一个开源的分布式存储平台,提供对象、块和文件存储功能。在 20.2.4 和 19.2.6 之前的版本中,Ceph 对象网关(RGW)的 SigV4 处理器不会拒绝那些携带了签名头集合中未包含的 头的请求,这使得任何持有预签名 URL 的用户都能附加任意的未签名 头,而 RGW 将会接受这些头。 AWS S3 要求 SigV4 请求中出现的每一个 头都必须包含在签名范围内,并会拒绝带有额外未签名头的请求;但 RGW 仅验证 中列出的头,而忽略其他额外的头,导致这些未签名的头也能生效。攻击者可以通过向预签名
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-50152 | 9.1 CRITICAL | Ceph Monitor subscription handler improperly authorizes config-key store reads, exposing c |
| CVE-2025-30156 | 8.9 HIGH | Ceph: AES-CBC misuse in CephX and RADOSGW enables authentication bypass and credential for |
| CVE-2026-39944 | 8.8 HIGH | Ceph: CephX AES Authentication error |
No comments yet