Описание
It was found Ceph versions before 13.2.4 that authenticated ceph users with read only permissions could steal dm-crypt encryption keys used in ceph disk encryption.
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | released | 12.2.11-0ubuntu0.18.04.1 |
| cosmic | not-affected | 13.2.4+dfsg1-0ubuntu0.18.10.1 |
| devel | not-affected | 13.2.4+dfsg1-0ubuntu1 |
| disco | not-affected | 13.2.4+dfsg1-0ubuntu1 |
| eoan | not-affected | 13.2.4+dfsg1-0ubuntu1 |
| esm-infra-legacy/trusty | released | 0.80.11-0ubuntu1.14.04.4+esm3 |
| esm-infra/bionic | released | 12.2.11-0ubuntu0.18.04.1 |
| esm-infra/focal | not-affected | 13.2.4+dfsg1-0ubuntu1 |
| esm-infra/xenial | released | 10.2.11-0ubuntu0.16.04.2 |
| focal | not-affected | 13.2.4+dfsg1-0ubuntu1 |
Показывать по
EPSS
2.7 Low
CVSS2
5.7 Medium
CVSS3
Связанные уязвимости
It was found Ceph versions before 13.2.4 that authenticated ceph users with read only permissions could steal dm-crypt encryption keys used in ceph disk encryption.
It was found Ceph versions before 13.2.4 that authenticated ceph users with read only permissions could steal dm-crypt encryption keys used in ceph disk encryption.
It was found Ceph versions before 13.2.4 that authenticated ceph users ...
It was found Ceph versions before 13.2.4 that authenticated ceph users with read only permissions could steal dm-crypt encryption keys used in ceph disk encryption.
Уязвимость системы хранения данных Ceph, связанная с ошибкой процедуры авторизации, позволяющая нарушителю получить несанкционированный доступ к ключам шифрования dm-crypt
EPSS
2.7 Low
CVSS2
5.7 Medium
CVSS3