cbcvebase.
CVE-2018-10861
published 2018-07-10

CVE-2018-10861: A flaw was found in the way ceph mon handles user requests. Any authenticated ceph user having read access to ceph can delete, create ceph storage pools and…

PriorityP345high8.1CVSS 3.0
AVNACLPRLUINSUCNIHAH
EPSS
3.25%
86.9th percentile
A flaw was found in the way ceph mon handles user requests. Any authenticated ceph user having read access to ceph can delete, create ceph storage pools and corrupt snapshot images. Ceph branches master, mimic, luminous and jewel are believed to be affected.

Affected

38 ranges· showing 25
VendorProductVersion rangeFixed in
cephceph
cephceph
cephceph
cephceph
cephceph
cephceph
cephceph
cephceph
cephceph
cephceph
cephceph
cephceph
cephceph
cephceph
cephceph
cephceph
cephceph
cephceph
cephceph
cephceph
cephceph
cephceph
debianceph< ceph 12.2.8+dfsg1-1 (bookworm)ceph 12.2.8+dfsg1-1 (bookworm)
debiandebian_linux
opensuseleap

CVSS provenance

nvdv3.08.1HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
nvdv2.05.5MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:P
osv8.1HIGH
vendor_debian8.1HIGH
vendor_redhat8.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.