Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2020-1759

Опубликовано: 13 апр. 2020
Источник: ubuntu
Приоритет: medium
CVSS2: 5.8
CVSS3: 6.4

Описание

A vulnerability was found in Red Hat Ceph Storage 4 and Red Hat Openshift Container Storage 4.2 where, A nonce reuse vulnerability was discovered in the secure mode of the messenger v2 protocol, which can allow an attacker to forge auth tags and potentially manipulate the data by leveraging the reuse of a nonce in a session. Messages encrypted using a reused nonce value are susceptible to serious confidentiality and integrity attacks.

РелизСтатусПримечание
bionic

not-affected

code not present
devel

not-affected

15.2.1-0ubuntu2
eoan

ignored

end of life
esm-infra-legacy/trusty

not-affected

code not present
esm-infra/bionic

not-affected

code not present
esm-infra/focal

not-affected

15.2.1-0ubuntu1
esm-infra/xenial

not-affected

code not present
focal

not-affected

15.2.1-0ubuntu1
precise/esm

not-affected

code not present
trusty

ignored

end of standard support

Показывать по

5.8 Medium

CVSS2

6.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.4
redhat
почти 6 лет назад

A vulnerability was found in Red Hat Ceph Storage 4 and Red Hat Openshift Container Storage 4.2 where, A nonce reuse vulnerability was discovered in the secure mode of the messenger v2 protocol, which can allow an attacker to forge auth tags and potentially manipulate the data by leveraging the reuse of a nonce in a session. Messages encrypted using a reused nonce value are susceptible to serious confidentiality and integrity attacks.

CVSS3: 6.4
nvd
почти 6 лет назад

A vulnerability was found in Red Hat Ceph Storage 4 and Red Hat Openshift Container Storage 4.2 where, A nonce reuse vulnerability was discovered in the secure mode of the messenger v2 protocol, which can allow an attacker to forge auth tags and potentially manipulate the data by leveraging the reuse of a nonce in a session. Messages encrypted using a reused nonce value are susceptible to serious confidentiality and integrity attacks.

CVSS3: 6.4
debian
почти 6 лет назад

A vulnerability was found in Red Hat Ceph Storage 4 and Red Hat Opensh ...

github
больше 3 лет назад

A vulnerability was found in Red Hat Ceph Storage 4 and Red Hat Openshift Container Storage 4.2 where, A nonce reuse vulnerability was discovered in the secure mode of the messenger v2 protocol, which can allow an attacker to forge auth tags and potentially manipulate the data by leveraging the reuse of a nonce in a session. Messages encrypted using a reused nonce value are susceptible to serious confidentiality and integrity attacks.

suse-cvrf
почти 6 лет назад

Security update for ceph

5.8 Medium

CVSS2

6.4 Medium

CVSS3