CVE-2017-16818: Medium severity redhat Ceph vulnerability
A flaw was discovered in ceph. Assertion in rgwiampolicy.cc can be reached by user input and fail through data passed in from a rest call causing it to crash.
Upstream patch:
https://github.com/ceph/ceph/commit/b3118cabb8060a8cc6a01c4e8264cb18e7b1745a
Other sources
RADOS Gateway in Ceph 12.1.0 through 12.2.1 allows remote authenticated users to cause a denial of service (assertion failure and application exit) by leveraging "full" (not necessarily admin) privileges to post an invalid profile to the admin API, related to rgw/rgwiampolicy.cc, rgw/rgwbasictypes.h, and rgw/rgwiamtypes.h.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2017-16818?
CVE-2017-16818 is a vulnerability in RADOS Gateway in Ceph 12.1.0 through 12.2.1 that allows remote authenticated users to cause a denial of service (assertion failure and application exit).
How can an attacker exploit CVE-2017-16818?
An attacker can exploit CVE-2017-16818 by leveraging "full" (not necessarily admin) privileges to post an invalid profile to the admin API.
What is the severity of CVE-2017-16818?
CVE-2017-16818 has a severity rating of medium (6.5).
Who is affected by CVE-2017-16818?
CVE-2017-16818 affects Red Hat Ceph versions 12.1.0 through 12.2.1 and Fedora 27.
How can I fix CVE-2017-16818?
To fix CVE-2017-16818, users should upgrade to a version of RADOS Gateway that is not affected by the vulnerability.