Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-10736

Опубликовано: 22 июн. 2020
Источник: nvd
CVSS3: 8
CVSS2: 5.2
EPSS Низкий

Описание

An authorization bypass vulnerability was found in Ceph versions 15.2.0 before 15.2.2, where the ceph-mon and ceph-mgr daemons do not properly restrict access, resulting in gaining access to unauthorized resources. This flaw allows an authenticated client to modify the configuration and possibly conduct further attacks.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:linuxfoundation:ceph:*:*:*:*:*:*:*:*
Версия от 15.2.0 (включая) до 15.2.2 (исключая)

EPSS

Процентиль: 21%
0.00068
Низкий

8 High

CVSS3

5.2 Medium

CVSS2

Дефекты

CWE-285
NVD-CWE-Other

Связанные уязвимости

CVSS3: 8
ubuntu
больше 5 лет назад

An authorization bypass vulnerability was found in Ceph versions 15.2.0 before 15.2.2, where the ceph-mon and ceph-mgr daemons do not properly restrict access, resulting in gaining access to unauthorized resources. This flaw allows an authenticated client to modify the configuration and possibly conduct further attacks.

CVSS3: 8
redhat
больше 5 лет назад

An authorization bypass vulnerability was found in Ceph versions 15.2.0 before 15.2.2, where the ceph-mon and ceph-mgr daemons do not properly restrict access, resulting in gaining access to unauthorized resources. This flaw allows an authenticated client to modify the configuration and possibly conduct further attacks.

CVSS3: 8
debian
больше 5 лет назад

An authorization bypass vulnerability was found in Ceph versions 15.2. ...

CVSS3: 8
github
больше 3 лет назад

An authorization bypass vulnerability was found in Ceph versions 15.2.0 before 15.2.2, where the ceph-mon and ceph-mgr daemons do not properly restrict access, resulting in gaining access to unauthorized resources. This flaw allows an authenticated client to modify the configuration and possibly conduct further attacks.

EPSS

Процентиль: 21%
0.00068
Низкий

8 High

CVSS3

5.2 Medium

CVSS2

Дефекты

CWE-285
NVD-CWE-Other