Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-31884

Источник: debian

Описание

Описание отсутствует

Пакеты

ПакетСтатусВерсия исправленияРелизТип
cephfixed18.2.8+ds-1package

Примечания

  • https://www.openwall.com/lists/oss-security/2026/01/21/6

  • https://github.com/ceph/ceph/security/advisories/GHSA-xj9f-7g59-m4jx

  • https://github.com/ceph/ceph/pull/66142

  • Fixed by: https://github.com/ceph/ceph/commit/5081933c9a0068fe9deba4fca2d943bda3168518 (v18.2.8)

Связанные уязвимости

ubuntu
7 месяцев назад

Incorrect usage of certificate checking via Pybind

CVSS3: 6.5
redhat
7 месяцев назад

A flaw was found in Ceph. An attacker can allow Ceph to accept any certificate because no certificate context is passed via Pybind to the constructors imaplib.IMAP4_SSL or smtplib.SMTP_SSL. As a result, pybind pybind does not check the server's X.509 certificate, instead accepting any certificate. This enables an attacker to commit a Man In the Middle (MITM) attack, compromising mail server credentials or mail contents

CVSS3: 6.5
fstec
9 месяцев назад

Уязвимость системы хранения данных Ceph, позволяющая нарушителю получить доступ к конфиденциальным данным или вызвать отказ в обслуживании