Insufficient Verification of Data Authenticity
CVE-2024-48916
Summary
A vulnerability in the Ceph Rados Gateway (RadosGW) OIDC provider, supplying a token with "none" as the algorithm (alg), an attacker can get around JWT signature verification. This occurs because the implementation fails to enforce strict signature validation, enabling attackers to forge valid tokens without a signature. This issue affects versions 16.1.0 through v19.3.0.
- LOW
- NETWORK
- HIGH
- UNCHANGED
- NONE
- LOW
- HIGH
- NONE
CWE-345 - Insufficient Verification of Data Authenticity
The software does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.
References
Advisory Timeline
- Published