Project

General

Profile

Actions

Bug #63004

closed

CVE-2023-43040 - Improperly verified POST keys.

Added by Christian Rohmann 8 months ago. Updated 7 months ago.

Status:
Resolved
Priority:
Normal
Assignee:
Target version:
% Done:

100%

Source:
Tags:
rgw backport_processed
Backport:
pacific quincy reef
Regression:
No
Severity:
2 - major
Reviewed:
Affected Versions:
ceph-qa-suite:
Pull request ID:
Crash signature (v1):
Crash signature (v2):

Description

There was a post / CVE reported (https://www.openwall.com/lists/oss-security/2023/09/26/10) about a security issue with RGW when dealing with POST keys.
There even is a patch / proposed fix attached to the report.

It seems strange there apparently is no report on this tracker yet?
I took the liberty to raise this now and kindly ask you to clarify if and how this is a real issue and what is happening to get this patched.


Files

s3-tests.patch (2.02 KB) s3-tests.patch s3test case Casey Bodley, 09/27/2023 04:55 PM
rgw.patch (1.68 KB) rgw.patch rgw bug fix Casey Bodley, 09/27/2023 04:55 PM

Related issues 3 (0 open3 closed)

Copied to rgw - Backport #63040: pacific: CVE-2023-43040 - Improperly verified POST keys.ResolvedCasey BodleyActions
Copied to rgw - Backport #63041: quincy: CVE-2023-43040 - Improperly verified POST keys.ResolvedCasey BodleyActions
Copied to rgw - Backport #63042: reef: CVE-2023-43040 - Improperly verified POST keys.ResolvedCasey BodleyActions
Actions

Also available in: Atom PDF