CVE-2017-16818: Fedoraproject Fedora
Medium severity, CVSS 6.5. EPSS: 2.3% chance of exploitation in the next 30 days.
RADOS Gateway in Ceph 12.1.0 through 12.2.1 allows remote authenticated users to cause a denial of service (assertion failure and application exit) by leveraging "full" (not necessarily admin) privileges to post an invalid profile to the admin API, related to rgw/rgw_iam_policy.cc, rgw/rgw_basic_types.h, and rgw/rgw_iam_types.h.
Affected products
- Fedoraproject Fedora: version 27 only
- Red Hat Ceph: from 12.1.0, up to and including 12.2.1
Published 2017-12-20. Last modified 2026-06-17.