CVE-2024-48916

HIGH8.1EPSS 0.04%

Ceph is vulnerable to authentication bypass through RadosGW

發布日:2025/7/30修改日:2026/4/30
也稱為:GHSA-5g9m-mmp6-93mqBIT-ceph-2024-48916

描述

Ceph is a distributed object, block, and file storage platform. In versions 19.2.3 and below, it is possible to send an JWT that has "none" as JWT alg. And by doing so the JWT signature is not checked. The vulnerability is most likely in the RadosGW OIDC provider. As of time of publication, a known patched version has yet to be published.

受影響套件(2)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1HIGH8.1CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

參考連結(3)