High severity7.5NVD Advisory· Published Oct 3, 2016· Updated May 6, 2026
CVE-2016-7031
CVE-2016-7031
Description
The RGW code in Ceph before 10.0.1, when authenticated-read ACL is applied to a bucket, allows remote attackers to list the bucket contents via a URL.
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- github.com/ceph/ceph/pull/6057nvdPatchVendor Advisory
- tracker.ceph.com/issues/13207nvdExploitIssue TrackingVendor Advisory
- docs.ceph.com/docs/master/release-notes/nvdRelease NotesVendor Advisory
- rhn.redhat.com/errata/RHSA-2016-1972.htmlnvdRelease NotesThird Party Advisory
- rhn.redhat.com/errata/RHSA-2016-1973.htmlnvd
- www.securityfocus.com/bid/93240nvd
News mentions
0No linked articles in our index yet.