Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-0670

Опубликовано: 25 июл. 2022
Источник: nvd
CVSS3: 9.1
EPSS Низкий

Описание

A flaw was found in Openstack manilla owning a Ceph File system "share", which enables the owner to read/write any manilla share or entire file system. The vulnerability is due to a bug in the "volumes" plugin in Ceph Manager. This allows an attacker to compromise Confidentiality and Integrity of a file system. Fixed in RHCS 5.2 and Ceph 17.2.2.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:linuxfoundation:ceph:*:*:*:*:*:*:*:*
Версия от 15.0.0 (включая) до 15.2.17 (исключая)
cpe:2.3:a:linuxfoundation:ceph:*:*:*:*:*:*:*:*
Версия от 16.0.0 (включая) до 16.2.10 (исключая)
cpe:2.3:a:linuxfoundation:ceph:*:*:*:*:*:*:*:*
Версия от 17.0.0 (включая) до 17.2.2 (исключая)
Конфигурация 2
cpe:2.3:a:redhat:ceph_storage:*:*:*:*:*:*:*:*
Версия до 5.2 (исключая)
Конфигурация 3

Одно из

cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*

EPSS

Процентиль: 42%
0.00196
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-863
NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 9.1
ubuntu
больше 3 лет назад

A flaw was found in Openstack manilla owning a Ceph File system "share", which enables the owner to read/write any manilla share or entire file system. The vulnerability is due to a bug in the "volumes" plugin in Ceph Manager. This allows an attacker to compromise Confidentiality and Integrity of a file system. Fixed in RHCS 5.2 and Ceph 17.2.2.

CVSS3: 8.1
redhat
больше 3 лет назад

A flaw was found in Openstack manilla owning a Ceph File system "share", which enables the owner to read/write any manilla share or entire file system. The vulnerability is due to a bug in the "volumes" plugin in Ceph Manager. This allows an attacker to compromise Confidentiality and Integrity of a file system. Fixed in RHCS 5.2 and Ceph 17.2.2.

CVSS3: 9.1
msrc
больше 3 лет назад

Описание отсутствует

CVSS3: 9.1
debian
больше 3 лет назад

A flaw was found in Openstack manilla owning a Ceph File system "share ...

CVSS3: 9.1
github
больше 3 лет назад

A flaw was found in Openstack manilla owning a Ceph File system "share", which enables the owner to read/write any manilla share or entire file system. The vulnerability is due to a bug in the "volumes" plugin in Ceph Manager. This allows an attacker to compromise Confidentiality and Integrity of a file system. Fixed in RHCS 5.2 and Ceph 17.2.2.

EPSS

Процентиль: 42%
0.00196
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-863
NVD-CWE-noinfo