PublicDateAtUSN: 2016-10-03 Candidate: CVE-2016-7031 PublicDate: 2016-10-03 18:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7031 https://ubuntu.com/security/notices/USN-3452-1 Description: The RGW code in Ceph before 10.0.1, when authenticated-read ACL is applied to a bucket, allows remote attackers to list the bucket contents via a URL. Ubuntu-Description: Notes: tyhicks> Fix present in 11.0.0, 10.1.0, and 10.0.1 tyhicks> Rados gateway code in Ubuntu 12.04 is significantly different. At this time, I'm not sure if it affected. leosilva> code affected is not present in precise Bugs: http://tracker.ceph.com/issues/13207 Priority: medium Discovered-by: Rahul Aggarwal Assigned-to: mdeslaur CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N [7.5 HIGH] Patches_ceph: upstream: https://github.com/ceph/ceph/commit/97bf0bcf02917fd772fbef73bb68e155feb84c1b upstream: https://github.com/ceph/ceph/commit/9ad73698f57598ae1302aaf175cb96082eb64961 upstream: https://github.com/ceph/ceph/pull/6057 upstream: https://github.com/ceph/ceph/pull/11045 upstream_ceph: needs-triage precise_ceph: ignored (reached end-of-life) precise/esm_ceph: not-affected (code not present) trusty_ceph: released (0.80.11-0ubuntu1.14.04.3) trusty/esm_ceph: released (0.80.11-0ubuntu1.14.04.3) vivid/stable-phone-overlay_ceph: DNE vivid/ubuntu-core_ceph: DNE xenial_ceph: not-affected (10.2.2-0ubuntu0.16.04.2) esm-infra/xenial_ceph: not-affected (10.2.2-0ubuntu0.16.04.2) yakkety_ceph: not-affected (10.2.2-0ubuntu5) zesty_ceph: not-affected (10.2.2-0ubuntu5) artful_ceph: not-affected (10.2.2-0ubuntu5) devel_ceph: not-affected (10.2.2-0ubuntu5)