The RGW code in Ceph before 10.0.1, when authenticated-read ACL is applied to a bucket, allows remote attackers to list the bucket contents via a URL.
{ "binaries": [ { "binary_name": "ceph", "binary_version": "0.80.11-0ubuntu1.14.04.3" }, { "binary_name": "ceph-common", "binary_version": "0.80.11-0ubuntu1.14.04.3" }, { "binary_name": "ceph-fs-common", "binary_version": "0.80.11-0ubuntu1.14.04.3" }, { "binary_name": "ceph-fuse", "binary_version": "0.80.11-0ubuntu1.14.04.3" }, { "binary_name": "ceph-mds", "binary_version": "0.80.11-0ubuntu1.14.04.3" }, { "binary_name": "ceph-resource-agents", "binary_version": "0.80.11-0ubuntu1.14.04.3" }, { "binary_name": "ceph-test", "binary_version": "0.80.11-0ubuntu1.14.04.3" }, { "binary_name": "libcephfs-dev", "binary_version": "0.80.11-0ubuntu1.14.04.3" }, { "binary_name": "libcephfs-java", "binary_version": "0.80.11-0ubuntu1.14.04.3" }, { "binary_name": "libcephfs-jni", "binary_version": "0.80.11-0ubuntu1.14.04.3" }, { "binary_name": "libcephfs1", "binary_version": "0.80.11-0ubuntu1.14.04.3" }, { "binary_name": "librados-dev", "binary_version": "0.80.11-0ubuntu1.14.04.3" }, { "binary_name": "librados2", "binary_version": "0.80.11-0ubuntu1.14.04.3" }, { "binary_name": "librbd-dev", "binary_version": "0.80.11-0ubuntu1.14.04.3" }, { "binary_name": "librbd1", "binary_version": "0.80.11-0ubuntu1.14.04.3" }, { "binary_name": "python-ceph", "binary_version": "0.80.11-0ubuntu1.14.04.3" }, { "binary_name": "radosgw", "binary_version": "0.80.11-0ubuntu1.14.04.3" }, { "binary_name": "rbd-fuse", "binary_version": "0.80.11-0ubuntu1.14.04.3" }, { "binary_name": "rest-bench", "binary_version": "0.80.11-0ubuntu1.14.04.3" } ], "availability": "No subscription required" }