CVE-2016-7031
published 2016-10-03CVE-2016-7031: The RGW code in Ceph before 10.0.1, when authenticated-read ACL is applied to a bucket, allows remote attackers to list the bucket contents via a URL.
PriorityP341high7.5CVSS 3.0
AVNACLPRNUINSUCHINAN
EPSS
1.75%
75.2th percentile
The RGW code in Ceph before 10.0.1, when authenticated-read ACL is applied to a bucket, allows remote attackers to list the bucket contents via a URL.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ceph_project | ceph | <= 10.0.0 | — |
| ceph_project | ceph | >= 0 < 10.2.5-1 | 10.2.5-1 |
| ceph_project | ceph | >= 0 < 10.2.5-1 | 10.2.5-1 |
| ceph_project | ceph | >= 0 < 10.2.5-1 | 10.2.5-1 |
| ceph_project | ceph | >= 0 < 10.2.5-1 | 10.2.5-1 |
| debian | ceph | < ceph 10.2.5-1 (bookworm) | ceph 10.2.5-1 (bookworm) |
| redhat | ceph | >= 0 < 0.80.11-0ubuntu1.14.04.3 | 0.80.11-0ubuntu1.14.04.3 |
| redhat | ceph_storage | <= 1.3.2 | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Ceph vulnerabilities
vendor_ubuntu·2017-10-11·CVSS 6.5
CVE-2016-5009 [MEDIUM] Ceph vulnerabilities
Title: Ceph vulnerabilities
Summary: Several security issues were fixed in Ceph.
It was discovered that Ceph incorrectly handled the handle_command
function. A remote authenticated user could use this issue to cause Ceph to
crash, resulting in a denial of service. (CVE-2016-5009)
Rahul Aggarwal discovered that Ceph incorrectly handled the
authenticated-read ACL. A remote attacker could possibly use this issue to
list bucket contents via a URL. (CVE-2016-7031)
Diluga Salome discovered that Ceph incorrectly handled certain POST objects
with null conditions. A remote attacker could possibly use this issue to
cuase Ceph to crash, resulting in a denial of service. (CVE-2016-8626)
Yang Liu discovered that Ceph incorrectly handled invalid HTTP Origin
headers. A remote attacker could possibly
Debian
CVE-2016-7031: ceph - The RGW code in Ceph before 10.0.1, when authenticated-read ACL is applied to a ...
vendor_debian·2016·CVSS 7.5
CVE-2016-7031 [HIGH] CVE-2016-7031: ceph - The RGW code in Ceph before 10.0.1, when authenticated-read ACL is applied to a ...
The RGW code in Ceph before 10.0.1, when authenticated-read ACL is applied to a bucket, allows remote attackers to list the bucket contents via a URL.
Scope: local
bookworm: resolved (fixed in 10.2.5-1)
bullseye: resolved (fixed in 10.2.5-1)
forky: resolved (fixed in 10.2.5-1)
sid: resolved (fixed in 10.2.5-1)
trixie: resolved (fixed in 10.2.5-1)
Red Hat
ceph: RGW permits bucket listing when authenticated_users=read
vendor_redhat·2015-09-23·CVSS 7.5
CVE-2016-7031 [HIGH] ceph: RGW permits bucket listing when authenticated_users=read
ceph: RGW permits bucket listing when authenticated_users=read
The RGW code in Ceph before 10.0.1, when authenticated-read ACL is applied to a bucket, allows remote attackers to list the bucket contents via a URL.
A flaw was found in Ceph RGW code which allows an anonymous user to list contents of RGW bucket by bypassing ACL which should only allow authenticated users to list contents of bucket.
Package: Ceph (OpenStack Foreman) - Not affected
Package: ceph (Red Hat Ceph Storage 2) - Not affected
Package: Ceph (Red Hat Enterprise Linux OpenStack Platform 5 (Icehouse)) - Not affected
Package: Ceph (Red Hat Enterprise Linux OpenStack Platform 6 (Juno)) - Not affected
Package: Ceph (Red Hat Enterprise Linux OpenStack Platform 6 (Juno) Installer) - Not affected
GHSA
GHSA-cfww-rhhj-3fwm: The RGW code in Ceph before 10
ghsa_unreviewed·2022-05-17
CVE-2016-7031 [HIGH] CWE-200 GHSA-cfww-rhhj-3fwm: The RGW code in Ceph before 10
The RGW code in Ceph before 10.0.1, when authenticated-read ACL is applied to a bucket, allows remote attackers to list the bucket contents via a URL.
OSV
ceph vulnerabilities
osv·2017-10-11·CVSS 6.5
CVE-2016-5009 [MEDIUM] ceph vulnerabilities
ceph vulnerabilities
It was discovered that Ceph incorrectly handled the handle_command
function. A remote authenticated user could use this issue to cause Ceph to
crash, resulting in a denial of service. (CVE-2016-5009)
Rahul Aggarwal discovered that Ceph incorrectly handled the
authenticated-read ACL. A remote attacker could possibly use this issue to
list bucket contents via a URL. (CVE-2016-7031)
Diluga Salome discovered that Ceph incorrectly handled certain POST objects
with null conditions. A remote attacker could possibly use this issue to
cuase Ceph to crash, resulting in a denial of service. (CVE-2016-8626)
Yang Liu discovered that Ceph incorrectly handled invalid HTTP Origin
headers. A remote attacker could possibly use this issue to cuase Ceph to
crash, resulting in a denial
OSV
CVE-2016-7031: The RGW code in Ceph before 10
osv·2016-10-03·CVSS 7.5
CVE-2016-7031 [HIGH] CVE-2016-7031: The RGW code in Ceph before 10
The RGW code in Ceph before 10.0.1, when authenticated-read ACL is applied to a bucket, allows remote attackers to list the bucket contents via a URL.
No detection rules found.
No public exploits indexed.
http://docs.ceph.com/docs/master/release-notes/#v10-0-1http://rhn.redhat.com/errata/RHSA-2016-1972.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1973.htmlhttp://tracker.ceph.com/issues/13207http://www.securityfocus.com/bid/93240https://github.com/ceph/ceph/pull/6057http://docs.ceph.com/docs/master/release-notes/#v10-0-1http://rhn.redhat.com/errata/RHSA-2016-1972.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1973.htmlhttp://tracker.ceph.com/issues/13207http://www.securityfocus.com/bid/93240https://github.com/ceph/ceph/pull/6057
2016-10-03
Published