Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-10861

Опубликовано: 09 июл. 2018
Источник: redhat
CVSS3: 4.6
EPSS Низкий

Описание

A flaw was found in the way ceph mon handles user requests. Any authenticated ceph user having read access to ceph can delete, create ceph storage pools and corrupt snapshot images. Ceph branches master, mimic, luminous and jewel are believed to be affected.

A flaw was found in the way ceph mon handles user requests. Any authenticated ceph user having read access to ceph can delete and corrupt snapshot images

Меры по смягчению последствий

Use mon_allow_pool_delete = false in ceph.conf to disable deletion of pools ~]$ for p in rados lspools do ceph osd pool set $p nodelete true done caveat: This mitigation does not protect against attacker from corrupting snapshot images

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7ceph-commonNot affected
Red Hat Enterprise Linux 8cephNot affected
Red Hat Ceph Storage 2.5cephFixedRHSA-2018:226126.07.2018
Red Hat Ceph Storage 2.5ceph-ansibleFixedRHSA-2018:226126.07.2018
Red Hat Ceph Storage 2 for UbuntucephFixedRHSA-2018:227426.07.2018
Red Hat Ceph Storage 3.0cephFixedRHSA-2018:217711.07.2018
Red Hat Ceph Storage 3.0ceph-ansibleFixedRHSA-2018:217711.07.2018
Red Hat Ceph Storage 3.0cephmetricsFixedRHSA-2018:217711.07.2018
Red Hat Ceph Storage 3.0nfs-ganeshaFixedRHSA-2018:217711.07.2018
Red Hat Ceph Storage 3 for UbuntucephFixedRHSA-2018:217911.07.2018

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-285
https://bugzilla.redhat.com/show_bug.cgi?id=1593308ceph: ceph-mon does not perform authorization on OSD pool ops

EPSS

Процентиль: 87%
0.03222
Низкий

4.6 Medium

CVSS3

Связанные уязвимости

CVSS3: 8.1
ubuntu
около 8 лет назад

A flaw was found in the way ceph mon handles user requests. Any authenticated ceph user having read access to ceph can delete, create ceph storage pools and corrupt snapshot images. Ceph branches master, mimic, luminous and jewel are believed to be affected.

CVSS3: 8.1
nvd
около 8 лет назад

A flaw was found in the way ceph mon handles user requests. Any authenticated ceph user having read access to ceph can delete, create ceph storage pools and corrupt snapshot images. Ceph branches master, mimic, luminous and jewel are believed to be affected.

CVSS3: 8.1
debian
около 8 лет назад

A flaw was found in the way ceph mon handles user requests. Any authen ...

CVSS3: 8.1
github
больше 4 лет назад

A flaw was found in the way ceph mon handles user requests. Any authenticated ceph user having read access to ceph can delete, create ceph storage pools and corrupt snapshot images. Ceph branches master, mimic, luminous and jewel are believed to be affected.

suse-cvrf
около 8 лет назад

Security update for ceph

EPSS

Процентиль: 87%
0.03222
Низкий

4.6 Medium

CVSS3