PT-2023-8462 · Ibm+4 · Ibm Spectrum Fusion Hci+4
Josh Baergen
+2
·
Published
2023-06-22
·
Updated
2025-09-25
·
CVE-2023-43040
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
IBM Spectrum Fusion HCI versions 2.5.2 through 2.7.2
Description
The issue is related to improper bucket access in the RGW service of the Ceph data storage system. It allows an attacker to perform unauthorized actions by exploiting the lack of access restrictions when handling bucket keys. This can enable a remote attacker to bypass security limitations and upload arbitrary files.
Recommendations
For IBM Spectrum Fusion HCI versions 2.5.2 through 2.7.2, consider restricting access to the RGW service until a patch is available. As a temporary workaround, limit the ability to write to buckets using the vulnerable
RGWPostObj ObjStore S3::get params() function. Avoid using the vulnerable function to process form-data containing keys that could allow unauthorized access to buckets. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Astra Linux
Debian
Ibm Spectrum Fusion Hci
Linuxmint
Ubuntu