USN-6613-1: Ceph vulnerability

Published Jan 29, 2024
·
Updated

Lucas Henry discovered that Ceph incorrectly handled specially crafted POST requests. An uprivileged user could use this to bypass Ceph's authorization checks and upload a file to any bucket.

Affected Software

32 affected componentsFixes available
All of the following
ubuntu/ceph<18.2.0-0ubuntu3.1
18.2.0-0ubuntu3.1
Ubuntu Ubuntu=23.10
All of the following
ubuntu/ceph-base<18.2.0-0ubuntu3.1
18.2.0-0ubuntu3.1
Ubuntu Ubuntu=23.10
All of the following
ubuntu/ceph-common<18.2.0-0ubuntu3.1
18.2.0-0ubuntu3.1
Ubuntu Ubuntu=23.10
All of the following
ubuntu/ceph<17.2.6-0ubuntu0.22.04.3
17.2.6-0ubuntu0.22.04.3
Ubuntu Ubuntu=22.04
All of the following
ubuntu/ceph-base<17.2.6-0ubuntu0.22.04.3
17.2.6-0ubuntu0.22.04.3
Ubuntu Ubuntu=22.04
All of the following
ubuntu/ceph-common<17.2.6-0ubuntu0.22.04.3
17.2.6-0ubuntu0.22.04.3
Ubuntu Ubuntu=22.04
All of the following
ubuntu/ceph<15.2.17-0ubuntu0.20.04.6
15.2.17-0ubuntu0.20.04.6
Ubuntu Ubuntu=20.04
All of the following
ubuntu/ceph-base<15.2.17-0ubuntu0.20.04.6
15.2.17-0ubuntu0.20.04.6
Ubuntu Ubuntu=20.04
All of the following
ubuntu/ceph-common<15.2.17-0ubuntu0.20.04.6
15.2.17-0ubuntu0.20.04.6
Ubuntu Ubuntu=20.04
All of the following
ubuntu/ceph<12.2.13-0ubuntu0.18.04.11+esm1
12.2.13-0ubuntu0.18.04.11+esm1
Ubuntu Ubuntu=18.04
All of the following
ubuntu/ceph-base<12.2.13-0ubuntu0.18.04.11+esm1
12.2.13-0ubuntu0.18.04.11+esm1
Ubuntu Ubuntu=18.04
All of the following
ubuntu/ceph-common<12.2.13-0ubuntu0.18.04.11+esm1
12.2.13-0ubuntu0.18.04.11+esm1
Ubuntu Ubuntu=18.04
All of the following
ubuntu/ceph<10.2.11-0ubuntu0.16.04.3+esm1
10.2.11-0ubuntu0.16.04.3+esm1
Ubuntu Ubuntu=16.04
All of the following
ubuntu/ceph-common<10.2.11-0ubuntu0.16.04.3+esm1
10.2.11-0ubuntu0.16.04.3+esm1
Ubuntu Ubuntu=16.04
All of the following
ubuntu/ceph<0.80.11-0ubuntu1.14.04.4+esm2
0.80.11-0ubuntu1.14.04.4+esm2
Ubuntu Ubuntu=14.04
All of the following
ubuntu/ceph-common<0.80.11-0ubuntu1.14.04.4+esm2
0.80.11-0ubuntu1.14.04.4+esm2
Ubuntu Ubuntu=14.04

Event History

Jan 29, 2024
Advisory Published
via Ubuntu·12:00 AM

Child vulnerabilities

Contains the following vulnerabilities.

Frequently Asked Questions

1

What is the vulnerability ID USN-6613-1 about?

The vulnerability ID USN-6613-1 concerns improper handling of specially crafted POST requests in Ceph, allowing unprivileged users to bypass authorization checks.

2

What are the affected versions for vulnerability ID USN-6613-1?

Affected versions for vulnerability ID USN-6613-1 include Ceph versions up to 18.2.0-0ubuntu3.1, 17.2.6-0ubuntu0.22.04.3, and 15.2.17-0ubuntu0.20.04.6, among others.

3

How do I fix vulnerability ID USN-6613-1?

To fix vulnerability ID USN-6613-1, upgrade Ceph to at least version 18.2.0-0ubuntu3.1, or apply the recommended patches for the specific version you are using.

4

What is the impact of vulnerability ID USN-6613-1?

The impact of vulnerability ID USN-6613-1 is that it allows unauthorized users to upload files to any bucket in Ceph, leading to potential data breaches.

5

Who discovered vulnerability ID USN-6613-1?

Vulnerability ID USN-6613-1 was discovered by researcher Lucas Henry.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203