Search CVE reports
11 – 20 of 42 results
CVE-2021-3531
Medium prioritySome fixes available 11 of 13
A flaw was found in the Red Hat Ceph Storage RGW in versions before 14.2.21. When processing a GET Request for a swift URL that ends with two slashes it can cause the rgw to crash, resulting in a denial of service. The greatest...
1 affected package
ceph
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
ceph | Fixed | Fixed | Fixed | Fixed | Vulnerable |
CVE-2021-3524
Medium prioritySome fixes available 11 of 13
A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway) in versions before 14.2.21. The vulnerability is related to the injection of HTTP headers via a CORS ExposeHeader tag. The newline character in...
1 affected package
ceph
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
ceph | Fixed | Fixed | Fixed | Fixed | Vulnerable |
CVE-2021-20288
Medium prioritySome fixes available 5 of 8
An authentication flaw was found in ceph in versions before 14.2.20. When the monitor handles CEPHX_GET_AUTH_SESSION_KEY requests, it doesn't sanitize other_keys, allowing key reuse. An attacker who can request a global_id can...
1 affected package
ceph
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
ceph | — | Fixed | Fixed | Ignored | Ignored |
CVE-2020-25678
Low priorityA flaw was found in ceph in versions prior to 16.y.z where ceph stores mgr module passwords in clear text. This can be found by searching the mgr logs for grafana and dashboard, with passwords visible.
1 affected package
ceph
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
ceph | — | Fixed | Fixed | Not affected | Not affected |
CVE-2020-27781
Medium prioritySome fixes available 11 of 13
User credentials can be manipulated and stolen by Native CephFS consumers of OpenStack Manila, resulting in potential privilege escalation. An Open Stack Manila user can request access to a share to an arbitrary cephx...
1 affected package
ceph
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
ceph | Fixed | Fixed | Fixed | Fixed | Vulnerable |
CVE-2020-25660
Medium priorityA flaw was found in the Cephx authentication protocol in versions before 15.2.6 and before 14.2.14, where it does not verify Ceph clients correctly and is then vulnerable to replay attacks in Nautilus. This flaw allows an attacker...
1 affected package
ceph
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
ceph | — | — | Fixed | Not affected | Not affected |
CVE-2020-10753
Medium prioritySome fixes available 12 of 14
A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway). The vulnerability is related to the injection of HTTP headers via a CORS ExposeHeader tag. The newline character in the ExposeHeader tag in the...
1 affected package
ceph
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
ceph | Fixed | Fixed | Fixed | Fixed | Fixed |
CVE-2020-10736
Medium prioritySome fixes available 2 of 3
An authorization bypass vulnerability was found in Ceph versions 15.2.0 before 15.2.2, where the ceph-mon and ceph-mgr daemons do not properly restrict access, resulting in gaining access to unauthorized resources. This flaw...
1 affected package
ceph
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
ceph | — | — | Fixed | Not affected | Not affected |
CVE-2020-1760
Medium prioritySome fixes available 2 of 4
A flaw was found in the Ceph Object Gateway, where it supports request sent by an anonymous user in Amazon S3. This flaw could lead to potential XSS attacks due to the lack of proper neutralization of untrusted input.
1 affected package
ceph
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
ceph | Not affected | Not affected | Not affected | Fixed | Fixed |
CVE-2020-12059
Medium priorityAn issue was discovered in Ceph through 13.2.9. A POST request with an invalid tagging XML can crash the RGW process by triggering a NULL pointer exception.
1 affected package
ceph
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
ceph | — | — | Not affected | Fixed | Not affected |