CVE-2024-48916: Ceph is vulnerable to authentication bypass through RadosGW

Published Dec 2, 2024
·
Updated

Authentication bypass in CEPH RadosGW

Other sources

Ceph is a distributed object, block, and file storage platform. In versions 19.2.3 and below, it is possible to send an JWT that has "none" as JWT alg. And by doing so the JWT signature is not checked. The vulnerability is most likely in the RadosGW OIDC provider. As of time of publication, a known patched version has yet to be published.

NVD

Ceph is vulnerable to authentication bypass through RadosGW

Microsoft

This vulnerability affects the RadosGW OIDC provider by allowing attackers to bypass authentication using JWTs with "none" as the algorithm (alg). The lack of signature enforcement creates a serious risk of unauthorized access and privilege escalation.

The vulnerability is probably in the RadosGW OIDC provider.

PoC

The HTTP request can be found below. But without the JWT:

POST / HTTP/2 Host: storage.xxx.se User-Agent: aws-sdk-go-v2/1.18.0 os/macos lang/go/1.21.1 X:nocoverageredesign md/GOOS/darwin md/GOARCH/arm64 api/sts/1.19.0 Content-Type: application/x-www-form-urlencoded Amz-Sdk-Invocation-Id: 30a74697-7d7e-4c02-b041-97d68156ee78 Amz-Sdk-Request: attempt=1; max=3 Content-Length: 1508 Accept-Encoding: gzip, deflate, br

Action=AssumeRoleWithWebIdentity&DurationSeconds=3600&RoleArn=arn%3Aaws%3Aiam%3A%3Aorgpentest002%3Arole%2Fu-pentest002STS&RoleSessionName=test&Version=2011-06-15&WebIdentityToken=ey..

Red Hat

Affected Software

6 affected componentsFixes available
debian/ceph<=16.2.11+ds-2
14.2.21-116.2.15+ds-0+deb12u118.2.4+ds-11
Microsoft cbl2 ceph 16.2.10-8
Microsoft cbl2 ceph 16.2.10-9
Microsoft azl3 ceph 18.2.2-9
Microsoft azl3 ceph 18.2.2-10
Microsoft cbl2 ceph 16.2.10-8

Event History

Dec 2, 2024
Data Sourced
via Red Hat·10:23 AM
DescriptionSeverityAffected Software
Jan 10, 2025
Data Sourced
via Ubuntu·06:15 PM
RemedyDescriptionSeverityAffected Software
Jul 30, 2025
CVE Published
via MITRE·07:45 PM
Data Sourced
via MITRE·07:45 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeakness
Aug 9, 2025
Data Sourced
via Microsoft·07:00 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·07:00 AM
Affected Software
Updated
via Microsoft·07:00 AM
SeverityAffected Software
Updated
via Microsoft·07:00 AM
DescriptionSeverity

Frequently Asked Questions

1

What is the severity of CVE-2024-48916?

The severity of CVE-2024-48916 is critical due to the potential for unauthorized access resulting from authentication bypass.

2

How do I fix CVE-2024-48916?

To mitigate CVE-2024-48916, upgrade to the patched versions of the Ceph package: 14.2.21-1, 16.2.15+ds-0+deb12u1, or 18.2.4+ds-11.

3

Which software is affected by CVE-2024-48916?

CVE-2024-48916 affects the Ceph RadosGW version up to and including 16.2.11+ds-2.

4

What are the implications of CVE-2024-48916?

The implications of CVE-2024-48916 include serious security risks due to the ability of attackers to bypass authentication.

5

Is there a patch available for CVE-2024-48916?

Yes, there are patches available for CVE-2024-48916 in the specified updated versions of the Ceph package.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203