CyberRota Analysis
AI-GeneratedA vulnerability in the signature verification logic of the NooBaa Multicloud Object Gateway allows attackers to exploit improperly validated S3 presigned URLs. By adding an unsigned x-amz-copy-source header to a valid presigned PUT URL, an attacker can escalate their permissions and perform unauthorized CopyObject operations, potentially accessing and copying sensitive data. Organizations using NooBaa should prioritize addressing this issue to safeguard their storage systems from unauthorized data manipulation.
Original NVD Description
A flaw was found in the signature verification logic of noobaa-core, the core component of the NooBaa Multicloud Object Gateway. The issue occurs when the service processes S3 presigned URLs using Signature Version 4 (SigV4). Due to improper validation, the service fails to reject requests containing unsigned x-amz- headers, instead simply dropping them from the signature calculation. This allows an attacker who possesses a valid presigned PUT URL to add an unsigned x-amz-copy-source header, effectively converting a simple upload into a CopyObject operation. This can lead to unauthorized access and copying of any data the original signer is permitted to reach across the entire storage system.