PT-2023-8462 · Ibm+4 · Ibm Spectrum Fusion Hci+4

Josh Baergen

+2

·

Published

2023-06-22

·

Updated

2025-09-25

·

CVE-2023-43040

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions IBM Spectrum Fusion HCI versions 2.5.2 through 2.7.2
Description The issue is related to improper bucket access in the RGW service of the Ceph data storage system. It allows an attacker to perform unauthorized actions by exploiting the lack of access restrictions when handling bucket keys. This can enable a remote attacker to bypass security limitations and upload arbitrary files.
Recommendations For IBM Spectrum Fusion HCI versions 2.5.2 through 2.7.2, consider restricting access to the RGW service until a patch is available. As a temporary workaround, limit the ability to write to buckets using the vulnerable RGWPostObj ObjStore S3::get params() function. Avoid using the vulnerable function to process form-data containing keys that could allow unauthorized access to buckets. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Weakness Enumeration

Related Identifiers

AZL-40646
BDU:2024-00898
CVE-2023-43040
DLA-3629-1
DLA-4310-1
DSA-5825-1
OESA-2023-1761
RHSA-2023:5693
RHSA-2024:0745
USN-6613-1

Affected Products

Astra Linux
Debian
Ibm Spectrum Fusion Hci
Linuxmint
Ubuntu