Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-1129

Опубликовано: 09 июл. 2018
Источник: redhat
CVSS3: 5.9
EPSS Низкий

Описание

A flaw was found in the way signature calculation was handled by cephx authentication protocol. An attacker having access to ceph cluster network who is able to alter the message payload was able to bypass signature checks done by cephx protocol. Ceph branches master, mimic, luminous and jewel are believed to be vulnerable.

A flaw was found in the way signature calculation was handled by cephx authentication protocol. An attacker having access to ceph cluster network, who is able to alter the message payload, was able to bypass signature checks done by cephx protocol.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ceph Storage 1.3cephWill not fix
Red Hat Enterprise Linux 7ceph-commonWill not fix
Red Hat Enterprise Linux 8cephNot affected
Red Hat Ceph Storage 2.5cephFixedRHSA-2018:226126.07.2018
Red Hat Ceph Storage 2.5ceph-ansibleFixedRHSA-2018:226126.07.2018
Red Hat Ceph Storage 2 for UbuntucephFixedRHSA-2018:227426.07.2018
Red Hat Ceph Storage 3.0cephFixedRHSA-2018:217711.07.2018
Red Hat Ceph Storage 3.0ceph-ansibleFixedRHSA-2018:217711.07.2018
Red Hat Ceph Storage 3.0cephmetricsFixedRHSA-2018:217711.07.2018
Red Hat Ceph Storage 3.0nfs-ganeshaFixedRHSA-2018:217711.07.2018

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-284

EPSS

Процентиль: 78%
0.01902
Низкий

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 8 лет назад

A flaw was found in the way signature calculation was handled by cephx authentication protocol. An attacker having access to ceph cluster network who is able to alter the message payload was able to bypass signature checks done by cephx protocol. Ceph branches master, mimic, luminous and jewel are believed to be vulnerable.

CVSS3: 6.5
nvd
около 8 лет назад

A flaw was found in the way signature calculation was handled by cephx authentication protocol. An attacker having access to ceph cluster network who is able to alter the message payload was able to bypass signature checks done by cephx protocol. Ceph branches master, mimic, luminous and jewel are believed to be vulnerable.

CVSS3: 6.5
msrc
6 месяцев назад

A flaw was found in the way signature calculation was handled by cephx authentication protocol. An attacker having access to ceph cluster network who is able to alter the message payload was able to bypass signature checks done by cephx protocol. Ceph branches master mimic luminous and jewel are believed to be vulnerable.

CVSS3: 6.5
debian
около 8 лет назад

A flaw was found in the way signature calculation was handled by cephx ...

CVSS3: 6.5
github
больше 4 лет назад

A flaw was found in the way signature calculation was handled by cephx authentication protocol. An attacker having access to ceph cluster network who is able to alter the message payload was able to bypass signature checks done by cephx protocol. Ceph branches master, mimic, luminous and jewel are believed to be vulnerable.

EPSS

Процентиль: 78%
0.01902
Низкий

5.9 Medium

CVSS3