Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-3979

Опубликовано: 11 янв. 2022
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

A key length flaw was found in Red Hat Ceph Storage. An attacker can exploit the fact that the key length is incorrectly passed in an encryption algorithm to create a non random key, which is weaker and can be exploited for loss of confidentiality and integrity on encrypted disks.

Отчет

Red Hat OpenStack Platform deployments use the ceph package directly from the Ceph channel; the RHOSP package will not be updated at this time.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ceph Storage 3cephOut of support scope
Red Hat Enterprise Linux 7ceph-commonNot affected
Red Hat Enterprise Linux 8cephNot affected
Red Hat Enterprise Linux 9cephNot affected
Red Hat Openshift Container Storage 4cephOut of support scope
Red Hat Openshift Data Foundation 4cephWill not fix
Red Hat OpenStack Platform 13 (Queens)cephWill not fix
Red Hat Ceph Storage 4.3cephFixedRHSA-2022:171605.05.2022
Red Hat Ceph Storage 5.1cephFixedRHSA-2022:117404.04.2022

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-287
https://bugzilla.redhat.com/show_bug.cgi?id=2024788ceph: Ceph volume does not honour osd_dmcrypt_key_size

EPSS

Процентиль: 46%
0.00229
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 3 лет назад

A key length flaw was found in Red Hat Ceph Storage. An attacker can exploit the fact that the key length is incorrectly passed in an encryption algorithm to create a non random key, which is weaker and can be exploited for loss of confidentiality and integrity on encrypted disks.

CVSS3: 6.5
nvd
больше 3 лет назад

A key length flaw was found in Red Hat Ceph Storage. An attacker can exploit the fact that the key length is incorrectly passed in an encryption algorithm to create a non random key, which is weaker and can be exploited for loss of confidentiality and integrity on encrypted disks.

CVSS3: 6.5
debian
больше 3 лет назад

A key length flaw was found in Red Hat Ceph Storage. An attacker can e ...

suse-cvrf
около 3 лет назад

Security update for ceph

suse-cvrf
больше 3 лет назад

Security update for ceph

EPSS

Процентиль: 46%
0.00229
Низкий

6.5 Medium

CVSS3