USN-6613-1: Ceph vulnerability
Lucas Henry discovered that Ceph incorrectly handled specially crafted POST requests. An uprivileged user could use this to bypass Ceph's authorization checks and upload a file to any bucket.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID USN-6613-1 about?
The vulnerability ID USN-6613-1 concerns improper handling of specially crafted POST requests in Ceph, allowing unprivileged users to bypass authorization checks.
What are the affected versions for vulnerability ID USN-6613-1?
Affected versions for vulnerability ID USN-6613-1 include Ceph versions up to 18.2.0-0ubuntu3.1, 17.2.6-0ubuntu0.22.04.3, and 15.2.17-0ubuntu0.20.04.6, among others.
How do I fix vulnerability ID USN-6613-1?
To fix vulnerability ID USN-6613-1, upgrade Ceph to at least version 18.2.0-0ubuntu3.1, or apply the recommended patches for the specific version you are using.
What is the impact of vulnerability ID USN-6613-1?
The impact of vulnerability ID USN-6613-1 is that it allows unauthorized users to upload files to any bucket in Ceph, leading to potential data breaches.
Who discovered vulnerability ID USN-6613-1?
Vulnerability ID USN-6613-1 was discovered by researcher Lucas Henry.