https://seclists.org/oss-sec/2023/q3/239: CVE-2023-43040 Ceph: Improperly verified POST keys.
Published Sep 26, 2023
·Updated
Affected Software
1 affected component
ceph Ceph RGW
Frequently Asked Questions
1
What is the severity of CVE-2023-43040?
CVE-2023-43040 has been classified as a moderate severity vulnerability.
2
How do I fix CVE-2023-43040?
To fix CVE-2023-43040, ensure that bucket permissions are properly configured and restrict access to trusted users only.
3
Who is affected by CVE-2023-43040?
CVE-2023-43040 affects installations of Ceph RGW that allow unprivileged users to write to accessible buckets.
4
What kind of attacks can be performed using CVE-2023-43040?
An attacker could exploit CVE-2023-43040 to upload files to any bucket they can access, leading to unauthorized data exposure.
5
When was CVE-2023-43040 published?
CVE-2023-43040 was published on September 26, 2023.