USN-8867-1: Ceph vulnerability
Ubuntu warns Ceph RGW may honor unsigned x-amz headers on presigned URLs, enabling privilege escalation.
Ubuntu Security Notice USN-8867-1 describes a flaw in the Ceph Object Gateway (RGW) SigV4 handler. RGW did not reject requests that carried x-amz-* headers absent from the signed header set. An attacker who already holds a presigned URL could attach arbitrary unsigned x-amz-* headers that RGW would honor, potentially escalating privileges beyond the signer's intent. The notice does not cite a CVE or report observed exploitation.
- USN-8867-1 covers a Ceph Object Gateway SigV4 request-handling flaw.
- RGW did not reject x-amz-* headers missing from the signed header set.
- A holder of a presigned URL could add unsigned headers RGW would honor.
- That could raise privileges beyond what the URL signer intended.
It was discovered that the Ceph Object Gateway (RGW) SigV4 handler did not reject requests carrying x-amz-* headers that were absent from the signed header set. An attacker holding a presigned URL could possibly use this issue to attach arbitrary unsigned x-amz-* headers that RGW would honor, allowing them to escalate their privileges beyond what the URL's signer intended.
This source does not provide full text. Read it at ubuntu.com.