Skip to main content

Insufficient Verification of Data Authenticity

CVE-2024-48916

Severity High
Score 8.1/10

Summary

A vulnerability in the Ceph Rados Gateway (RadosGW) OIDC provider, supplying a token with "none" as the algorithm (alg), an attacker can get around JWT signature verification. This occurs because the implementation fails to enforce strict signature validation, enabling attackers to forge valid tokens without a signature. This issue affects versions 16.1.0 through v19.3.0.

  • LOW
  • NETWORK
  • HIGH
  • UNCHANGED
  • NONE
  • LOW
  • HIGH
  • NONE

CWE-345 - Insufficient Verification of Data Authenticity

The software does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

Advisory Timeline

  • Published