8.8 HIGH
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): Low (L)
- User Interaction (UI): None (N)
- Scope (S): Unchanged (U)
- Confidentiality (C): High (H)
- Integrity (I): High (H)
- Availability (A): High (H)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): Low (L)
- Modified User Interaction (MUI): None (N)
- Modified Confidentiality (MC): High (H)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): High (H)
- Modified Availability (MA): High (H)
Activity log
- Created suggestion
Ceph: CephX AES Authentication error
Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2.4 and 19.2.6, the RADOS Gateway (RGW) protects STS session tokens with an AES-128-CBC handler that provides no message authentication, allowing an attacker who holds any valid STS token to tamper with it undetected and escalate to full RGW administrative access. Because the ciphertext is unauthenticated, the attacker can perform a CBC bit-flip on the acct_type, perm_type, and is_admin fields of their own token, and a forged is_admin value triggers a global administrative override that bypasses all capability checks. The attack is reachable remotely over the RGW S3 endpoint and is a self-contained modification of a token the attacker already possesses, requiring no encryption oracle and no network observation. It requires only a single valid STS token, which need not carry any elevated privileges, with STS enabled. This issue is fixed in versions 20.2.4 and 19.2.6.
References
-
https://github.com/ceph/ceph/security/advisories/GHSA-j73r-qrgx-jvq2 x_refsource_CONFIRM
-
https://github.com/ceph/ceph/releases/tag/v19.2.6 x_refsource_MISC
-
https://github.com/ceph/ceph/releases/tag/v20.2.4 x_refsource_MISC
Affected products
- ==>= 19.0.0, < 19.2.6
- ==>= 20.0.0, < 20.2.4
Matching in nixpkgs
pkgs.ceph
Distributed storage system
pkgs.calceph
C library for interacting with binary planetary ephemeris files, such INPOPxx, JPL DExxx and SPICE
pkgs.libceph
Distributed storage system
pkgs.ceph-csi
Container Storage Interface (CSI) driver for Ceph RBD and CephFS
pkgs.ceph-dev
Distributed storage system
pkgs.ceph-client
Distributed storage system
pkgs.kubectl-rook-ceph
Krew plugin to run kubectl commands with rook-ceph
pkgs.sbclPackages.cephes
None
-
nixos-unstable 20260101-git
- nixpkgs-unstable 20260101-git
- nixos-unstable-small 20260101-git
-
nixos-26.05 20260101-git
- nixos-26.05-small 20260101-git
- nixpkgs-26.05-darwin 20260101-git
Package maintainers
-
@kiranshila Kiran Shila <me@kiranshila.com>
-
@alexanderkjeldaas Alexander Kjeldaas <ak@formalprivacy.com>
-
@johanot Johan Thomsen <write@ownrisk.dk>
-
@krav Kristoffer Thømt Ravneberg <kristoffer@microdisko.no>
-
@adevress Adrien Devresse <adev@adev.name>
-
@benaryorg benaryorg <binary@benary.org>
-
@nh2 Niklas Hambüchen <mail@nh2.me>
-
@vinylen Victor Nilsson <victor@viclab.se>
-
@nagy Daniel Nagy <danielnagy@posteo.de>
-
@7c6f434c Michael Raskin <7c6f434c@mail.ru>
-
@Uthar Kasper Gałkowski <galkowskikasper@gmail.com>
-
@lukego Luke Gorrie <luke@snabb.co>
-
@hraban Hraban Luyat <hraban@0brg.net>