CVE-2023-43040
IBM Spectrum Fusion HCI improper access control
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
IBM Spectrum Fusion HCI 2.5.2 through 2.7.2 could allow an attacker to perform unauthorized actions in RGW for Ceph due to improper bucket access. IBM X-Force ID: 266807.
IBM Spectrum Fusion HCI 2.5.2 a 2.7.2 podría permitir que un atacante realice acciones no autorizadas en RGW para Ceph debido a un acceso inadecuado al depósito. ID de IBM X-Force: 266807.
A flaw was found in rgw. This flaw allows an unprivileged user to write to any bucket(s) accessible by a given key if a POST's form-data contains a key called 'bucket' with a value matching the bucket's name used to sign the request. This issue results in a user being able to upload to any bucket accessible by the specified access key as long as the bucket in the POST policy matches the bucket in the said POST form part.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2023-09-15 CVE Reserved
- 2024-01-30 CVE Published
- 2024-05-13 EPSS Updated
- 2024-07-29 First Exploit
- 2024-08-02 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-1220: Insufficient Granularity of Access Control
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/266807 | Vdb Entry |
URL | Date | SRC |
---|---|---|
https://github.com/riza/CVE-2023-43040 | 2024-07-29 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.ibm.com/support/pages/node/7151040 | 2024-05-14 | |
https://access.redhat.com/security/cve/CVE-2023-43040 | 2024-02-08 | |
https://bugzilla.redhat.com/show_bug.cgi?id=2216855 | 2024-02-08 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
IBM Search vendor "IBM" | Spectrum Fusion HCI Search vendor "IBM" for product "Spectrum Fusion HCI" | >= 2.5.2 <= 2.7.2 Search vendor "IBM" for product "Spectrum Fusion HCI" and version " >= 2.5.2 <= 2.7.2" | en |
Affected
|