Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 7

Количество 7

ubuntu логотип

CVE-2024-48916

около 1 года назад

Ceph is a distributed object, block, and file storage platform. In versions 19.2.3 and below, it is possible to send an JWT that has "none" as JWT alg. And by doing so the JWT signature is not checked. The vulnerability is most likely in the RadosGW OIDC provider. As of time of publication, a known patched version has yet to be published.

CVSS3: 8.1
EPSS: Низкий
redhat логотип

CVE-2024-48916

почти 2 года назад

Ceph is a distributed object, block, and file storage platform. In versions 19.2.3 and below, it is possible to send an JWT that has "none" as JWT alg. And by doing so the JWT signature is not checked. The vulnerability is most likely in the RadosGW OIDC provider. As of time of publication, a known patched version has yet to be published.

CVSS3: 9.1
EPSS: Низкий
nvd логотип

CVE-2024-48916

около 1 года назад

Ceph is a distributed object, block, and file storage platform. In versions 19.2.3 and below, it is possible to send an JWT that has "none" as JWT alg. And by doing so the JWT signature is not checked. The vulnerability is most likely in the RadosGW OIDC provider. As of time of publication, a known patched version has yet to be published.

CVSS3: 8.1
EPSS: Низкий
msrc логотип

CVE-2024-48916

около 1 года назад

Ceph is vulnerable to authentication bypass through RadosGW

CVSS3: 8.1
EPSS: Низкий
debian логотип

CVE-2024-48916

около 1 года назад

Ceph is a distributed object, block, and file storage platform. In ver ...

CVSS3: 8.1
EPSS: Низкий
fstec логотип

BDU:2025-00001

почти 2 года назад

Уязвимость демона radosgw системы хранения данных Ceph, позволяющая нарушителю обойти процедуру аутентификации

CVSS3: 8.1
EPSS: Низкий
redos логотип

ROS-20250905-04

около 1 года назад

Уязвимость ceph

CVSS3: 8.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2024-48916

Ceph is a distributed object, block, and file storage platform. In versions 19.2.3 and below, it is possible to send an JWT that has "none" as JWT alg. And by doing so the JWT signature is not checked. The vulnerability is most likely in the RadosGW OIDC provider. As of time of publication, a known patched version has yet to be published.

CVSS3: 8.1
0%
Низкий
около 1 года назад
redhat логотип
CVE-2024-48916

Ceph is a distributed object, block, and file storage platform. In versions 19.2.3 and below, it is possible to send an JWT that has "none" as JWT alg. And by doing so the JWT signature is not checked. The vulnerability is most likely in the RadosGW OIDC provider. As of time of publication, a known patched version has yet to be published.

CVSS3: 9.1
0%
Низкий
почти 2 года назад
nvd логотип
CVE-2024-48916

Ceph is a distributed object, block, and file storage platform. In versions 19.2.3 and below, it is possible to send an JWT that has "none" as JWT alg. And by doing so the JWT signature is not checked. The vulnerability is most likely in the RadosGW OIDC provider. As of time of publication, a known patched version has yet to be published.

CVSS3: 8.1
0%
Низкий
около 1 года назад
msrc логотип
CVE-2024-48916

Ceph is vulnerable to authentication bypass through RadosGW

CVSS3: 8.1
0%
Низкий
около 1 года назад
debian логотип
CVE-2024-48916

Ceph is a distributed object, block, and file storage platform. In ver ...

CVSS3: 8.1
0%
Низкий
около 1 года назад
fstec логотип
BDU:2025-00001

Уязвимость демона radosgw системы хранения данных Ceph, позволяющая нарушителю обойти процедуру аутентификации

CVSS3: 8.1
0%
Низкий
почти 2 года назад
redos логотип
ROS-20250905-04

Уязвимость ceph

CVSS3: 8.1
0%
Низкий
около 1 года назад

Уязвимостей на страницу