Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-54330

Опубликовано: 19 авг. 2026
Источник: redhat
CVSS3: 8.2
EPSS Низкий

Описание

Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2.4 and 19.2.6, the Ceph Object Gateway (RGW) SigV4 handler does not reject requests that carry x-amz-* headers absent from the signed header set, allowing anyone holding a presigned URL to attach arbitrary unsigned x-amz-* headers that RGW will honor. AWS S3 requires every x-amz-* header on a SigV4 request to be signed and rejects requests bearing additional unsigned headers, but RGW validates only the headers listed in X-Amz-SignedHeaders and ignores any extra ones, so they take effect without being covered by the signature. By adding such headers to a presigned PUT URL, an attacker can grant themselves more capabilities than the URL's signer intended and escalate their privileges. This issue is fixed in versions 20.2.4 and 19.2.6.

A flaw was found in Ceph RGW's SigV4 signature verification handler. When processing S3 requests, RGW verifies only the headers explicitly listed in the X-Amz-SignedHeaders field but does not reject requests that carry additional unsigned x-amz-* headers. This diverges from the AWS S3 specification, which requires all x-amz-* headers to be signed. As a result, anyone holding a presigned PUT URL can attach arbitrary unsigned x-amz-* headers that RGW will honor, effectively escalating their privileges beyond what the original URL signer authorized. This can lead to unauthorized access to and modification of S3 objects.

Отчет

The Red Hat Product Security team has assessed the severity of this vulnerability as Important, given that exploitation requires only a presigned PUT URL and knowledge of the SigV4 protocol gap. Successful exploitation allows an attacker to escalate privileges beyond the scope intended by the presigned URL signer, gaining unauthorized read and write access to S3 objects. The vulnerability's root cause is incomplete signature verification in RGW's SigV4 handler, which fails to reject requests containing unsigned x-amz-* headers.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ceph Storage 4cephFix deferred
Red Hat Ceph Storage 5cephFix deferred
Red Hat Ceph Storage 6cephFix deferred
Red Hat Ceph Storage 7cephFix deferred
Red Hat Ceph Storage 7rhceph/rhceph-7-rhel9Fix deferred
Red Hat Ceph Storage 8cephFix deferred
Red Hat Ceph Storage 8rhceph/rhceph-8-rhel9Fix deferred
Red Hat Ceph Storage 9cephFix deferred
Red Hat Ceph Storage 9rhceph/rhceph-9-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-347
https://bugzilla.redhat.com/show_bug.cgi?id=2519428ceph: ceph: RGW SigV4 verifier allows attachment of arbitrary unsigned x-amz-* headers leading to privilege escalation

EPSS

Процентиль: 8%
0.00181
Низкий

8.2 High

CVSS3

Связанные уязвимости

CVSS3: 8.1
ubuntu
9 дней назад

Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2.4 and 19.2.6, the Ceph Object Gateway (RGW) SigV4 handler does not reject requests that carry x-amz-* headers absent from the signed header set, allowing anyone holding a presigned URL to attach arbitrary unsigned x-amz-* headers that RGW will honor. AWS S3 requires every x-amz-* header on a SigV4 request to be signed and rejects requests bearing additional unsigned headers, but RGW validates only the headers listed in X-Amz-SignedHeaders and ignores any extra ones, so they take effect without being covered by the signature. By adding such headers to a presigned PUT URL, an attacker can grant themselves more capabilities than the URL's signer intended and escalate their privileges. This issue is fixed in versions 20.2.4 and 19.2.6.

CVSS3: 8.1
nvd
9 дней назад

Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2.4 and 19.2.6, the Ceph Object Gateway (RGW) SigV4 handler does not reject requests that carry x-amz-* headers absent from the signed header set, allowing anyone holding a presigned URL to attach arbitrary unsigned x-amz-* headers that RGW will honor. AWS S3 requires every x-amz-* header on a SigV4 request to be signed and rejects requests bearing additional unsigned headers, but RGW validates only the headers listed in X-Amz-SignedHeaders and ignores any extra ones, so they take effect without being covered by the signature. By adding such headers to a presigned PUT URL, an attacker can grant themselves more capabilities than the URL's signer intended and escalate their privileges. This issue is fixed in versions 20.2.4 and 19.2.6.

msrc
4 дня назад

Ceph RGW SigV4 handler accepts unsigned x-amz-* headers on presigned requests, allowing privilege escalation

CVSS3: 8.1
debian
9 дней назад

Ceph is an open-source distributed storage platform providing object, ...

EPSS

Процентиль: 8%
0.00181
Низкий

8.2 High

CVSS3

Уязвимость CVE-2026-54330