216.73.216.133

CVE-2024-48916

· Published 30/07/2025 20:15 · Modified 31/07/2025 18:42

Labels: CVE-2024-48916 2025-07-30CVE-2024-48916CWE-345[email protected]

Essential information

Published
30/07/2025 20:15
Modified
31/07/2025 18:42
Author
Creator
CVSS
8.1 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

CVSS metrics

Description

Ceph is a distributed object, block, and file storage platform. In versions 19.2.3 and below, it is possible to send an JWT that has "none" as JWT alg. And by doing so the JWT signature is not checked. The vulnerability is most likely in the RadosGW OIDC provider. As of time of publication, a known patched version has yet to be published.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
ceph / ceph cpe:2.3:a:ceph:ceph:<19.2.3:*:*:*:*:*:*:*

References