cbcvebase.
CVE-2024-48916
published 2025-07-30

CVE-2024-48916: Ceph is a distributed object, block, and file storage platform. In versions 19.2.3 and below, it is possible to send an JWT that has "none" as JWT alg. And by…

PriorityP347high8.1CVSS 3.1
AVNACLPRLUINSUCHIHAN
EPSS
0.19%
9.1th percentile
Ceph is a distributed object, block, and file storage platform. In versions 19.2.3 and below, it is possible to send an JWT that has "none" as JWT alg. And by doing so the JWT signature is not checked. The vulnerability is most likely in the RadosGW OIDC provider. As of time of publication, a known patched version has yet to be published.

Affected

9 ranges
VendorProductVersion rangeFixed in
cephceph<= 19.2.3
cephceph>= 0 < 16.2.15+ds-0+deb12u116.2.15+ds-0+deb12u1
cephceph>= 0 < 18.2.4+ds-1118.2.4+ds-11
cephceph>= 0 < 18.2.4+ds-1118.2.4+ds-11
debianceph< ceph 16.2.15+ds-0+deb12u1 (bookworm)ceph 16.2.15+ds-0+deb12u1 (bookworm)
msrcazl3_ceph_18.2.2-10_on_azure_linux_3.0
msrcazl3_ceph_18.2.2-9_on_azure_linux_3.0
msrccbl2_ceph_16.2.10-8_on_cbl_mariner_2.0
msrccbl2_ceph_16.2.10-9_on_cbl_mariner_2.0

CVSS provenance

nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
osv8.1HIGH
vendor_debian8.1HIGH
vendor_msrc8.1HIGH
vendor_redhat8.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.