CVE-2016-7031: Infoleak
The RGW code in Ceph before 10.0.1, when authenticated-read ACL is applied to a bucket, allows remote attackers to list the bucket contents via a URL.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-7031?
CVE-2016-7031 has a moderate severity level as it allows authenticated users to list the contents of a bucket due to a misconfiguration in the ACL settings.
How do I fix CVE-2016-7031?
To fix CVE-2016-7031, upgrade Ceph to version 10.0.1 or later, or properly configure the access control lists to prevent unauthorized access.
What software versions are affected by CVE-2016-7031?
CVE-2016-7031 affects Ceph versions prior to 10.0.1 and Red Hat Ceph Storage versions up to 1.3.2.
Can CVE-2016-7031 be exploited remotely?
Yes, CVE-2016-7031 can be exploited remotely by attackers who have authenticated access to the affected bucket.
What is the impact of CVE-2016-7031 on my system?
The impact of CVE-2016-7031 may result in unauthorized users being able to list sensitive data stored in your Ceph buckets.