Database/Control plane, storage & DevOps

Ceph RGW (IBM Spectrum Fusion HCI): Improper bucket access lets an actor perform unauthorized actions in RGW
CVSS 6.5CVE-2023-43040Control plane, storage & DevOpscurated
Impact
Improper bucket access lets an actor perform unauthorized actions in RGW
Who can reach it
Network (remote)
What to do
Control-plane: RGW/appliance firmware upgrade; re-audit bucket policies
References
Related entries
- Keycloak: Regex complexity in SearchQueryUtilsCVE-2024-10270 · KeycloakMedium
- Intel Data Center GPU Max Series 1100 / 1550: A second improper conditions check in the Max Series allowingCVE-2024-24580 · Intel Data Center GPU Max Series 1100 / 1550Medium
- Apache Kafka (client): ConfigProvider plugins let an untrusted app read files/env of the Kafka client hostCVE-2024-31141 · Apache Kafka (client)Medium
- Intel Distribution of OpenVINO Model Server: An unauthenticated user can reach an input-validation flaw in OpenVINOCVE-2024-32048 · Intel Distribution of OpenVINO Model ServerMedium
- GitLab EE: crafted SCIM provisioning input triggers an unbounded loop and takes the instance downCVE-2025-10903 · GitLab EE (SCIM user provisioning)Medium
- rpc.mountd: NFSv3 client bypasses export restrictions and root_squash on subdirectoriesCVE-2025-12801 · nfs-utils rpc.mountd (NFSv3 export subtree access)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.