V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
BDU:2024-00898
BDU
MediumConfirmedExploit available

Уязвимость функции RGWPostObj_ObjStore_S3::get_params() (rgw_rest_s3.cc) службы RGW системы хранения данных Ceph связана с недостатками раз…

CVSS
6.3
Medium
EPSS
0.00
p0
Published
2024-01-01
Updated
2024-01-01
Description

Уязвимость функции RGWPostObj_ObjStore_S3::get_params() (rgw_rest_s3.cc) службы RGW системы хранения данных Ceph связана с недостатками разграничения доступа при обработке ключей корзины. Эксплуатация уязвимости может позволить нарушителю, действующему удаленно, обойти ограничения безопасности и загрузить произвольные файлы

Affected products
Red hat inc. Red hat ceph storageRed hat inc. Red hat ceph storageRed hat inc. Red hat ceph storageRed hat inc. Red hat ceph storageRed hat inc. Red hat ceph storageRed hat inc. Red hat ceph storageRed hat inc. Red hat ceph storageRed hat inc. Red hat ceph storageRed hat inc. Red hat ceph storageRed hat inc. Red hat ceph storageRed hat inc. Red hat ceph storageRed hat inc. Red hat ceph storageRed hat inc. Red hat ceph storageRed hat inc. Red hat ceph storageRed hat inc. Red hat ceph storageRed hat inc. Red hat ceph storageRed hat inc. Red hat ceph storageRed hat inc. Red hat ceph storageRed hat inc. Red hat ceph storageRed hat inc. Red hat ceph storage
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Timeline
2024-01-01
Published
2024-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: L
Low (L)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: L
Low (L)
Integrity Impact
I: L
Low (L)
Availability Impact
A: L
Low (L)
Exploit indicators
EPSS
0.000 · p0
Known exploited (KEV)
No
Known exploits — Сканер-ВС
CVE-2023-43040
github-poc · https://github.com/riza/CVE-2023-43040
Enterprise
Affected software
ProductVendorStatus
red hat ceph storagered hat inc.Tracked
red hat ceph storagered hat inc.Tracked
red hat ceph storagered hat inc.Tracked
red hat ceph storagered hat inc.Tracked
red hat ceph storagered hat inc.Tracked
red hat ceph storagered hat inc.Tracked
red hat ceph storagered hat inc.Tracked
red hat ceph storagered hat inc.Tracked
red hat ceph storagered hat inc.Tracked
red hat ceph storagered hat inc.Tracked
red hat ceph storagered hat inc.Tracked
red hat ceph storagered hat inc.Tracked
red hat ceph storagered hat inc.Tracked
red hat ceph storagered hat inc.Tracked
red hat ceph storagered hat inc.Tracked
red hat ceph storagered hat inc.Tracked
red hat ceph storagered hat inc.Tracked
red hat ceph storagered hat inc.Tracked
red hat ceph storagered hat inc.Tracked
red hat ceph storagered hat inc.Tracked