Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-10861

Опубликовано: 09 июл. 2018
Источник: redhat
CVSS3: 4.6
EPSS Низкий

Описание

A flaw was found in the way ceph mon handles user requests. Any authenticated ceph user having read access to ceph can delete, create ceph storage pools and corrupt snapshot images. Ceph branches master, mimic, luminous and jewel are believed to be affected.

A flaw was found in the way ceph mon handles user requests. Any authenticated ceph user having read access to ceph can delete and corrupt snapshot images

Меры по смягчению последствий

Use mon_allow_pool_delete = false in ceph.conf to disable deletion of pools ~]$ for p in rados lspools do ceph osd pool set $p nodelete true done caveat: This mitigation does not protect against attacker from corrupting snapshot images

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7ceph-commonNot affected
Red Hat Enterprise Linux 8cephNot affected
Red Hat Ceph Storage 2.5cephFixedRHSA-2018:226126.07.2018
Red Hat Ceph Storage 2.5ceph-ansibleFixedRHSA-2018:226126.07.2018
Red Hat Ceph Storage 2 for UbuntuFixedRHSA-2018:227426.07.2018
Red Hat Ceph Storage 3.0cephFixedRHSA-2018:217711.07.2018
Red Hat Ceph Storage 3.0ceph-ansibleFixedRHSA-2018:217711.07.2018
Red Hat Ceph Storage 3.0cephmetricsFixedRHSA-2018:217711.07.2018
Red Hat Ceph Storage 3.0nfs-ganeshaFixedRHSA-2018:217711.07.2018
Red Hat Ceph Storage 3 for UbuntuFixedRHSA-2018:217911.07.2018

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-285
https://bugzilla.redhat.com/show_bug.cgi?id=1593308ceph: ceph-mon does not perform authorization on OSD pool ops

EPSS

Процентиль: 68%
0.0058
Низкий

4.6 Medium

CVSS3

Связанные уязвимости

CVSS3: 8.1
ubuntu
больше 7 лет назад

A flaw was found in the way ceph mon handles user requests. Any authenticated ceph user having read access to ceph can delete, create ceph storage pools and corrupt snapshot images. Ceph branches master, mimic, luminous and jewel are believed to be affected.

CVSS3: 8.1
nvd
больше 7 лет назад

A flaw was found in the way ceph mon handles user requests. Any authenticated ceph user having read access to ceph can delete, create ceph storage pools and corrupt snapshot images. Ceph branches master, mimic, luminous and jewel are believed to be affected.

CVSS3: 8.1
debian
больше 7 лет назад

A flaw was found in the way ceph mon handles user requests. Any authen ...

CVSS3: 8.1
github
больше 3 лет назад

A flaw was found in the way ceph mon handles user requests. Any authenticated ceph user having read access to ceph can delete, create ceph storage pools and corrupt snapshot images. Ceph branches master, mimic, luminous and jewel are believed to be affected.

suse-cvrf
больше 7 лет назад

Security update for ceph

EPSS

Процентиль: 68%
0.0058
Низкий

4.6 Medium

CVSS3