<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 14:54:32 +0000</lastBuildDate>
    <item>
      <title>bdu:2024-00898</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-00898</link>
      <description>bdu:2024-00898</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-00898</guid>
    </item>
    <item>
      <title>certfr-2024-avi-0627 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Certaines d'entre elles permettent à un attaq…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0627</link>
      <description>certfr-2024-avi-0627</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0627</guid>
    </item>
    <item>
      <title>EUVD-2026-259870</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-259870</link>
      <description>EUVD-2026-259870</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-259870</guid>
    </item>
    <item>
      <title>fkie_cve-2023-43040</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-43040</link>
      <description>&lt;p&gt;IBM Spectrum Fusion HCI 2.5.2 through 2.7.2 could allow an attacker to perform unauthorized actions in RGW for Ceph due to improper bucket access.  IBM X-Force ID:  266807.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;IBM Spectrum Fusion HCI 2.5.2 through 2.7.2 could allow an attacker to perform unauthorized actions in RGW for Ceph due to improper bucket access.  IBM X-Force ID:  266807.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-43040</guid>
    </item>
    <item>
      <title>GHSA-fwhj-j6cr-5qw4</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-fwhj-j6cr-5qw4</link>
      <description>&lt;p&gt;IBM Spectrum Fusion HCI 2.5.2 through 2.7.2 could allow an attacker to perform unauthorized actions in RGW for Ceph due to improper bucket access.  IBM X-Force ID:  266807.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;IBM Spectrum Fusion HCI 2.5.2 through 2.7.2 could allow an attacker to perform unauthorized actions in RGW for Ceph due to improper bucket access.  IBM X-Force ID:  266807.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-fwhj-j6cr-5qw4</guid>
    </item>
    <item>
      <title>gsd-2023-43040</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-43040</link>
      <description>gsd-2023-43040</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-43040</guid>
    </item>
    <item>
      <title>msrc_CVE-2023-43040 — IBM Spectrum Fusion HCI improper access control</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2023-43040</link>
      <description>msrc_CVE-2023-43040</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2023-43040</guid>
    </item>
    <item>
      <title>OESA-2023-1761 — ceph security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2023-1761</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: ceph, openEuler:20.03-LTS-SP3: ceph, openEuler:22.03-LTS: ceph, openEuler:22.03-LTS-SP1: ceph, openEuler:22.03-LTS-SP2: ceph&lt;/p&gt;
&lt;p&gt;Ceph is a massively scalable, open-source, distributed storage system that runs on commodity hardware and delivers object, block and file system storage.&#13;
&#13;
Security Fix(es):&#13;
&#13;
A flaw was found in rgw. This flaw allows an unprivileged user to write to any bucket(s) accessible by a given key if a POST&amp;amp;apos;s form-data contains a key called &amp;amp;apos;bucket&amp;amp;apos; with a value matching the bucket&amp;amp;apos;s name used to sign the request. This issue results in a user being able to upload to any bucket accessible by the specified access key as long as the bucket in the POST policy matches the bucket in the said POST form part.(CVE-2023-43040)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: ceph, openEuler:20.03-LTS-SP3: ceph, openEuler:22.03-LTS: ceph, openEuler:22.03-LTS-SP1: ceph, openEuler:22.03-LTS-SP2: ceph&lt;/p&gt;
&lt;p&gt;Ceph is a massively scalable, open-source, distributed storage system that runs on commodity hardware and delivers object, block and file system storage.&#13;
&#13;
Security Fix(es):&#13;
&#13;
A flaw was found in rgw. This flaw allows an unprivileged user to write to any bucket(s) accessible by a given key if a POST&amp;amp;apos;s form-data contains a key called &amp;amp;apos;bucket&amp;amp;apos; with a value matching the bucket&amp;amp;apos;s name used to sign the request. This issue results in a user being able to upload to any bucket accessible by the specified access key as long as the bucket in the POST policy matches the bucket in the said POST form part.(CVE-2023-43040)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2023-1761</guid>
    </item>
    <item>
      <title>RHSA-2023:5693 — Red Hat Security Advisory: Red Hat Ceph Storage 6.1 security, enhancement, and bug fix update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2023:5693</link>
      <description>&lt;p&gt;bootstrap: Cross-site Scripting (XSS) in the data-target property of scrollspy bootstrap: XSS in the tooltip data-viewport attribute bootstrap: XSS in the affix configuration target property rgw: improperly verified POST keys ceph: RGW crash upon misconfigured CORS rule&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;bootstrap: Cross-site Scripting (XSS) in the data-target property of scrollspy bootstrap: XSS in the tooltip data-viewport attribute bootstrap: XSS in the affix configuration target property rgw: improperly verified POST keys ceph: RGW crash upon misconfigured CORS rule&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2023:5693</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2023-43040</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-43040</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: ceph, Ubuntu:Pro:16.04:LTS: ceph, Ubuntu:Pro:18.04:LTS: ceph, Ubuntu:20.04:LTS: ceph, Ubuntu:22.04:LTS: ceph, Ubuntu:24.04:LTS: ceph&lt;/p&gt;
&lt;p&gt;IBM Spectrum Fusion HCI 2.5.2 through 2.7.2 could allow an attacker to perform unauthorized actions in RGW for Ceph due to improper bucket access.  IBM X-Force ID:  266807.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: ceph, Ubuntu:Pro:16.04:LTS: ceph, Ubuntu:Pro:18.04:LTS: ceph, Ubuntu:20.04:LTS: ceph, Ubuntu:22.04:LTS: ceph, Ubuntu:24.04:LTS: ceph&lt;/p&gt;
&lt;p&gt;IBM Spectrum Fusion HCI 2.5.2 through 2.7.2 could allow an attacker to perform unauthorized actions in RGW for Ceph due to improper bucket access.  IBM X-Force ID:  266807.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-43040</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-0331 — Red Hat Ceph Storage: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0331</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Red Hat Ceph Storage ausnutzen, um Dateien zu manipulieren oder einen Denial of Service Zustand herbeizuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Red Hat Ceph Storage ausnutzen, um Dateien zu manipulieren oder einen Denial of Service Zustand herbeizuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0331</guid>
    </item>
  </channel>
</rss>
