Database/Control plane, storage & DevOps
Ceph RADOS Gateway (RGW): RGW accepts a JWT whose header declares alg "none" and never checks the signature, so anyone
Impact
RGW accepts a JWT whose header declares alg "none" and never checks the signature, so anyone who can reach the gateway can mint a token claiming to be any OIDC identity. That is a full authentication bypass on the S3 endpoint - the attacker assumes another tenant's role and reads or writes their buckets.
Who can reach it
Any client that can open a TCP connection to the RGW S3/STS endpoint. Only affects clusters with OIDC/STS AssumeRoleWithWebIdentity configured, but there is no valid credential requirement at all.
What to do
Upgrade RGW to a release past 19.2.3 that carries the fix and restart every radosgw daemon. Until then disable the OIDC/STS web-identity provider on the gateway, or front it with a proxy that rejects tokens whose alg header is not the one your IdP actually signs with.
References
Related entries
- Ceph RADOS Gateway (RGW): A POST carrying malformed object-tagging XML dereferences a NULL pointer and kills theCVE-2020-12059 · Ceph RADOS Gateway (RGW)High
- Ceph RADOS Gateway (RGW): One malformed PUT kills the radosgw process. Sending an object copy with an emptyCVE-2024-47866 · Ceph RADOS Gateway (RGW)High
- HPE Insight Remote Support (Java deserialization): Java deserialization letting an unauthenticated attacker executeCVE-2024-53673 · HPE Insight Remote Support (Java deserialization)High
- PostgreSQL (libpq): Improper quoting in PQescape*CVE-2025-1094 · PostgreSQL (libpq)High
- HPE Performance Cluster Manager (HPCM) GUI authentication bypass: Authentication bypass in the HPCM web GUICVE-2025-27086 · HPE Performance Cluster Manager (HPCM) GUI authentication bypassHigh
- HTCondor (IDToken authorization restrictions): The per-token authorization restrictions attached withCVE-2025-30093 · HTCondor (IDToken authorization restrictions)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.