Fedora Account System
Red Hat Associate
Red Hat Customer
Improper verification of cryptographic signature vulnerability in Ceph RGW's SigV4 handler. The flaw is caused by RGW only verifying the validity of headers listed in X-Amz-SignedHeaders without checking whether additional unsigned x-amz-* headers are present on the request. AWS S3 requires every x-amz-* header to be signed and rejects requests carrying unsigned headers, but RGW does not enforce this check. An attacker holding only a presigned PUT URL can attach arbitrary x-amz-* headers that RGW applies, granting more capabilities than the original signer intended, resulting in privilege escalation.