Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-23g5-cwwr-8xhw

Опубликовано: 26 авг. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

A key length flaw was found in Red Hat Ceph Storage. An attacker can exploit the fact that the key length is incorrectly passed in an encryption algorithm to create a non random key, which is weaker and can be exploited for loss of confidentiality and integrity on encrypted disks.

A key length flaw was found in Red Hat Ceph Storage. An attacker can exploit the fact that the key length is incorrectly passed in an encryption algorithm to create a non random key, which is weaker and can be exploited for loss of confidentiality and integrity on encrypted disks.

EPSS

Процентиль: 42%
0.00199
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-287
CWE-327

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 3 года назад

A key length flaw was found in Red Hat Ceph Storage. An attacker can exploit the fact that the key length is incorrectly passed in an encryption algorithm to create a non random key, which is weaker and can be exploited for loss of confidentiality and integrity on encrypted disks.

CVSS3: 6.5
redhat
больше 3 лет назад

A key length flaw was found in Red Hat Ceph Storage. An attacker can exploit the fact that the key length is incorrectly passed in an encryption algorithm to create a non random key, which is weaker and can be exploited for loss of confidentiality and integrity on encrypted disks.

CVSS3: 6.5
nvd
почти 3 года назад

A key length flaw was found in Red Hat Ceph Storage. An attacker can exploit the fact that the key length is incorrectly passed in an encryption algorithm to create a non random key, which is weaker and can be exploited for loss of confidentiality and integrity on encrypted disks.

CVSS3: 6.5
debian
почти 3 года назад

A key length flaw was found in Red Hat Ceph Storage. An attacker can e ...

suse-cvrf
больше 2 лет назад

Security update for ceph

EPSS

Процентиль: 42%
0.00199
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-287
CWE-327