Логотип exploitDog
bind:"CVE-2020-27781"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2020-27781"

Количество 10

Количество 10

ubuntu логотип

CVE-2020-27781

около 5 лет назад

User credentials can be manipulated and stolen by Native CephFS consumers of OpenStack Manila, resulting in potential privilege escalation. An Open Stack Manila user can request access to a share to an arbitrary cephx user, including existing users. The access key is retrieved via the interface drivers. Then, all users of the requesting OpenStack project can view the access key. This enables the attacker to target any resource that the user has access to. This can be done to even "admin" users, compromising the ceph administrator. This flaw affects Ceph versions prior to 14.2.16, 15.x prior to 15.2.8, and 16.x prior to 16.2.0.

CVSS3: 7.1
EPSS: Низкий
redhat логотип

CVE-2020-27781

около 5 лет назад

User credentials can be manipulated and stolen by Native CephFS consumers of OpenStack Manila, resulting in potential privilege escalation. An Open Stack Manila user can request access to a share to an arbitrary cephx user, including existing users. The access key is retrieved via the interface drivers. Then, all users of the requesting OpenStack project can view the access key. This enables the attacker to target any resource that the user has access to. This can be done to even "admin" users, compromising the ceph administrator. This flaw affects Ceph versions prior to 14.2.16, 15.x prior to 15.2.8, and 16.x prior to 16.2.0.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2020-27781

около 5 лет назад

User credentials can be manipulated and stolen by Native CephFS consumers of OpenStack Manila, resulting in potential privilege escalation. An Open Stack Manila user can request access to a share to an arbitrary cephx user, including existing users. The access key is retrieved via the interface drivers. Then, all users of the requesting OpenStack project can view the access key. This enables the attacker to target any resource that the user has access to. This can be done to even "admin" users, compromising the ceph administrator. This flaw affects Ceph versions prior to 14.2.16, 15.x prior to 15.2.8, and 16.x prior to 16.2.0.

CVSS3: 7.1
EPSS: Низкий
debian логотип

CVE-2020-27781

около 5 лет назад

User credentials can be manipulated and stolen by Native CephFS consum ...

CVSS3: 7.1
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2021:0079-1

около 5 лет назад

Security update for ceph

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2020:2327-1

около 5 лет назад

Security update for ceph

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:0023-1

около 5 лет назад

Security update for ceph

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2020:3895-1

около 5 лет назад

Security update for ceph

EPSS: Низкий
github логотип

GHSA-mh9p-7vgq-83jw

больше 3 лет назад

User credentials can be manipulated and stolen by Native CephFS consumers of OpenStack Manila, resulting in potential privilege escalation. An Open Stack Manila user can request access to a share to an arbitrary cephx user, including existing users. The access key is retrieved via the interface drivers. Then, all users of the requesting OpenStack project can view the access key. This enables the attacker to target any resource that the user has access to. This can be done to even "admin" users, compromising the ceph administrator. This flaw affects Ceph versions prior to 16.2.0.

CVSS3: 7.1
EPSS: Низкий
fstec логотип

BDU:2021-06304

около 5 лет назад

Уязвимость системы хранения данных Ceph, связанная с недостаточной защитой регистрационных данных, позволяющая нарушителю получить доступ к конфиденциальным данным и нарушить их целостность

CVSS3: 7.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2020-27781

User credentials can be manipulated and stolen by Native CephFS consumers of OpenStack Manila, resulting in potential privilege escalation. An Open Stack Manila user can request access to a share to an arbitrary cephx user, including existing users. The access key is retrieved via the interface drivers. Then, all users of the requesting OpenStack project can view the access key. This enables the attacker to target any resource that the user has access to. This can be done to even "admin" users, compromising the ceph administrator. This flaw affects Ceph versions prior to 14.2.16, 15.x prior to 15.2.8, and 16.x prior to 16.2.0.

CVSS3: 7.1
0%
Низкий
около 5 лет назад
redhat логотип
CVE-2020-27781

User credentials can be manipulated and stolen by Native CephFS consumers of OpenStack Manila, resulting in potential privilege escalation. An Open Stack Manila user can request access to a share to an arbitrary cephx user, including existing users. The access key is retrieved via the interface drivers. Then, all users of the requesting OpenStack project can view the access key. This enables the attacker to target any resource that the user has access to. This can be done to even "admin" users, compromising the ceph administrator. This flaw affects Ceph versions prior to 14.2.16, 15.x prior to 15.2.8, and 16.x prior to 16.2.0.

CVSS3: 7.1
0%
Низкий
около 5 лет назад
nvd логотип
CVE-2020-27781

User credentials can be manipulated and stolen by Native CephFS consumers of OpenStack Manila, resulting in potential privilege escalation. An Open Stack Manila user can request access to a share to an arbitrary cephx user, including existing users. The access key is retrieved via the interface drivers. Then, all users of the requesting OpenStack project can view the access key. This enables the attacker to target any resource that the user has access to. This can be done to even "admin" users, compromising the ceph administrator. This flaw affects Ceph versions prior to 14.2.16, 15.x prior to 15.2.8, and 16.x prior to 16.2.0.

CVSS3: 7.1
0%
Низкий
около 5 лет назад
debian логотип
CVE-2020-27781

User credentials can be manipulated and stolen by Native CephFS consum ...

CVSS3: 7.1
0%
Низкий
около 5 лет назад
suse-cvrf логотип
openSUSE-SU-2021:0079-1

Security update for ceph

0%
Низкий
около 5 лет назад
suse-cvrf логотип
openSUSE-SU-2020:2327-1

Security update for ceph

0%
Низкий
около 5 лет назад
suse-cvrf логотип
SUSE-SU-2021:0023-1

Security update for ceph

0%
Низкий
около 5 лет назад
suse-cvrf логотип
SUSE-SU-2020:3895-1

Security update for ceph

0%
Низкий
около 5 лет назад
github логотип
GHSA-mh9p-7vgq-83jw

User credentials can be manipulated and stolen by Native CephFS consumers of OpenStack Manila, resulting in potential privilege escalation. An Open Stack Manila user can request access to a share to an arbitrary cephx user, including existing users. The access key is retrieved via the interface drivers. Then, all users of the requesting OpenStack project can view the access key. This enables the attacker to target any resource that the user has access to. This can be done to even "admin" users, compromising the ceph administrator. This flaw affects Ceph versions prior to 16.2.0.

CVSS3: 7.1
0%
Низкий
больше 3 лет назад
fstec логотип
BDU:2021-06304

Уязвимость системы хранения данных Ceph, связанная с недостаточной защитой регистрационных данных, позволяющая нарушителю получить доступ к конфиденциальным данным и нарушить их целостность

CVSS3: 7.1
0%
Низкий
около 5 лет назад

Уязвимостей на страницу