CVE-2018-1128
published 2018-07-10CVE-2018-1128: It was found that cephx authentication protocol did not verify ceph clients correctly and was vulnerable to replay attack. Any attacker having access to ceph…
PriorityP340high7.5CVSS 3.0
AVAACHPRNUINSUCHIHAH
EPSS
1.37%
68.9th percentile
It was found that cephx authentication protocol did not verify ceph clients correctly and was vulnerable to replay attack. Any attacker having access to ceph cluster network who is able to sniff packets on network can use this vulnerability to authenticate with ceph service and perform actions allowed by ceph service. Ceph branches master, mimic, luminous and jewel are believed to be vulnerable.
Affected
36 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ceph | < ceph 14.2.15-1 (bookworm) | ceph 14.2.15-1 (bookworm) |
| debian | ceph | < ceph 12.2.8+dfsg1-1 (bookworm) | ceph 12.2.8+dfsg1-1 (bookworm) |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | linux | < ceph 12.2.8+dfsg1-1 (bookworm) | ceph 12.2.8+dfsg1-1 (bookworm) |
| fedoraproject | fedora | — | — |
| linux | linux_kernel | >= 0 < 4.19.9-1 | 4.19.9-1 |
| linux | linux_kernel | >= 0 < 4.19.9-1 | 4.19.9-1 |
| linux | linux_kernel | >= 0 < 4.19.9-1 | 4.19.9-1 |
| linux | linux_kernel | >= 0 < 4.19.9-1 | 4.19.9-1 |
| linuxfoundation | ceph | >= 0 < 15.2.7-0ubuntu0.20.04.2 | 15.2.7-0ubuntu0.20.04.2 |
| opensuse | leap | — | — |
| redhat | ceph | < 14.2.14 | 14.2.14 |
| redhat | ceph | — | — |
| redhat | ceph | >= 0 < 12.2.8+dfsg1-1 | 12.2.8+dfsg1-1 |
| redhat | ceph | >= 0 < 14.2.15-1 | 14.2.15-1 |
| redhat | ceph | >= 0 < 12.2.8+dfsg1-1 | 12.2.8+dfsg1-1 |
| redhat | ceph | >= 0 < 14.2.15-1 | 14.2.15-1 |
| redhat | ceph | >= 0 < 12.2.8+dfsg1-1 | 12.2.8+dfsg1-1 |
| redhat | ceph | >= 0 < 14.2.15-1 | 14.2.15-1 |
| redhat | ceph | >= 0 < 12.2.8+dfsg1-1 | 12.2.8+dfsg1-1 |
| redhat | ceph | >= 0 < 14.2.15-1 | 14.2.15-1 |
| redhat | ceph | 10.2.0 – 13.2.1 | — |
| redhat | ceph | >= 15.0.0 < 15.2.6 | 15.2.6 |
| redhat | ceph_storage | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.05.4MEDIUMAV:A/AC:M/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-457q-vj84-7r8r: A flaw was found in the Cephx authentication protocol in versions before 15
ghsa_unreviewed·2022-05-24·CVSS 7.5
CVE-2020-25660 [HIGH] CWE-294 GHSA-457q-vj84-7r8r: A flaw was found in the Cephx authentication protocol in versions before 15
A flaw was found in the Cephx authentication protocol in versions before 15.2.6 and before 14.2.14, where it does not verify Ceph clients correctly and is then vulnerable to replay attacks in Nautilus. This flaw allows an attacker with access to the Ceph cluster network to authenticate with the Ceph service via a packet sniffer and perform actions allowed by the Ceph service. This issue is a reintroduction of CVE-2018-1128, affecting the msgr2 protocol. The msgr 2 protocol is used for all communication except older clients that do not support the msgr2 protocol. The msgr1 protocol is not affected. The highest threat from this vulnerability is to confidentiality, integrity, and system availability.
GHSA
GHSA-xw3f-9qfw-v43f: It was found that cephx authentication protocol did not verify ceph clients correctly and was vulnerable to replay attack
ghsa_unreviewed·2022-05-13
CVE-2018-1128 [HIGH] CWE-287 GHSA-xw3f-9qfw-v43f: It was found that cephx authentication protocol did not verify ceph clients correctly and was vulnerable to replay attack
It was found that cephx authentication protocol did not verify ceph clients correctly and was vulnerable to replay attack. Any attacker having access to ceph cluster network who is able to sniff packets on network can use this vulnerability to authenticate with ceph service and perform actions allowed by ceph service. Ceph branches master, mimic, luminous and jewel are believed to be vulnerable.
OSV
ceph vulnerabilities
osv·2021-01-28·CVSS 7.5
CVE-2020-10736 [HIGH] ceph vulnerabilities
ceph vulnerabilities
Olle Segerdahl found that ceph-mon and ceph-mgr daemons did not properly
restrict access, resulting in gaining access to unauthorized resources. An
authenticated user could use this vulnerability to modify the configuration and
possibly conduct further attacks. (CVE-2020-10736)
Adam Mohammed found that Ceph Object Gateway was vulnerable to HTTP header
injection via a CORS ExposeHeader tag. An attacker could use this to gain access
or cause a crash. (CVE-2020-10753)
Ilya Dryomov found that Cephx authentication did not verify Ceph clients
correctly and was then vulnerable to replay attacks in Nautilus. An attacker
could use the Ceph cluster network to authenticate via a packet sniffer and
perform actions. This issue is a reintroduction of CVE-2018-1128.
(CVE-2020-2566
OSV
CVE-2020-25660: A flaw was found in the Cephx authentication protocol in versions before 15
osv·2020-11-23·CVSS 7.5
CVE-2020-25660 [HIGH] CVE-2020-25660: A flaw was found in the Cephx authentication protocol in versions before 15
A flaw was found in the Cephx authentication protocol in versions before 15.2.6 and before 14.2.14, where it does not verify Ceph clients correctly and is then vulnerable to replay attacks in Nautilus. This flaw allows an attacker with access to the Ceph cluster network to authenticate with the Ceph service via a packet sniffer and perform actions allowed by the Ceph service. This issue is a reintroduction of CVE-2018-1128, affecting the msgr2 protocol. The msgr 2 protocol is used for all communication except older clients that do not support the msgr2 protocol. The msgr1 protocol is not affected. The highest threat from this vulnerability is to confidentiality, integrity, and system availability.
Kernel
libceph: add authorizer challenge
kernel_security·2018-07-27·CVSS 7.5
CVE-2018-1128 [HIGH] libceph: add authorizer challenge
libceph: add authorizer challenge
When a client authenticates with a service, an authorizer is sent with
a nonce to the service (ceph_x_authorize_[ab]) and the service responds
with a mutation of that nonce (ceph_x_authorize_reply). This lets the
client verify the service is who it says it is but it doesn't protect
against a replay: someone can trivially capture the exchange and reuse
the same authorizer to authenticate themselves.
Allow the service to reject an initial authorizer with a random
challenge (ceph_x_authorize_challenge). The client then has to respond
with an updated authorizer proving they are able to decrypt the
service's challenge and that the new authorizer was produced for this
specific connection instance.
The accepting side requires this challenge and response uncond
OSV
CVE-2018-1128: It was found that cephx authentication protocol did not verify ceph clients correctly and was vulnerable to replay attack
osv·2018-07-10·CVSS 7.5
CVE-2018-1128 [HIGH] CVE-2018-1128: It was found that cephx authentication protocol did not verify ceph clients correctly and was vulnerable to replay attack
It was found that cephx authentication protocol did not verify ceph clients correctly and was vulnerable to replay attack. Any attacker having access to ceph cluster network who is able to sniff packets on network can use this vulnerability to authenticate with ceph service and perform actions allowed by ceph service. Ceph branches master, mimic, luminous and jewel are believed to be vulnerable.
Ubuntu
Ceph vulnerabilities
vendor_ubuntu·2021-01-28·CVSS 7.5
CVE-2020-10753 [HIGH] Ceph vulnerabilities
Title: Ceph vulnerabilities
Summary: Several security issues were fixed in Ceph.
Olle Segerdahl found that ceph-mon and ceph-mgr daemons did not properly
restrict access, resulting in gaining access to unauthorized resources. An
authenticated user could use this vulnerability to modify the configuration and
possibly conduct further attacks. (CVE-2020-10736)
Adam Mohammed found that Ceph Object Gateway was vulnerable to HTTP header
injection via a CORS ExposeHeader tag. An attacker could use this to gain access
or cause a crash. (CVE-2020-10753)
Ilya Dryomov found that Cephx authentication did not verify Ceph clients
correctly and was then vulnerable to replay attacks in Nautilus. An attacker
could use the Ceph cluster network to authenticate via a packet sniffer and
perform actions. Th
Red Hat
ceph: CEPHX_V2 replay attack protection lost
vendor_redhat·2020-11-17·CVSS 7.5
CVE-2020-25660 [HIGH] CWE-294 ceph: CEPHX_V2 replay attack protection lost
ceph: CEPHX_V2 replay attack protection lost
A flaw was found in the Cephx authentication protocol in versions before 15.2.6 and before 14.2.14, where it does not verify Ceph clients correctly and is then vulnerable to replay attacks in Nautilus. This flaw allows an attacker with access to the Ceph cluster network to authenticate with the Ceph service via a packet sniffer and perform actions allowed by the Ceph service. This issue is a reintroduction of CVE-2018-1128, affecting the msgr2 protocol. The msgr 2 protocol is used for all communication except older clients that do not support the msgr2 protocol. The msgr1 protocol is not affected. The highest threat from this vulnerability is to confidentiality, integrity, and system availability.
A flaw was found in the Cephx authentication p
Debian
CVE-2020-25660: ceph - A flaw was found in the Cephx authentication protocol in versions before 15.2.6 ...
vendor_debian·2020·CVSS 7.5
CVE-2020-25660 [HIGH] CVE-2020-25660: ceph - A flaw was found in the Cephx authentication protocol in versions before 15.2.6 ...
A flaw was found in the Cephx authentication protocol in versions before 15.2.6 and before 14.2.14, where it does not verify Ceph clients correctly and is then vulnerable to replay attacks in Nautilus. This flaw allows an attacker with access to the Ceph cluster network to authenticate with the Ceph service via a packet sniffer and perform actions allowed by the Ceph service. This issue is a reintroduction of CVE-2018-1128, affecting the msgr2 protocol. The msgr 2 protocol is used for all communication except older clients that do not support the msgr2 protocol. The msgr1 protocol is not affected. The highest threat from this vulnerability is to confidentiality, integrity, and system availability.
Scope: local
bookworm: resolved (fixed in 14.2.15-1)
bullseye: resolved (fixed in 14.2.15-1)
Red Hat
ceph: cephx protocol is vulnerable to replay attack
vendor_redhat·2018-07-09·CVSS 7.5
CVE-2018-1128 [HIGH] CWE-294 ceph: cephx protocol is vulnerable to replay attack
ceph: cephx protocol is vulnerable to replay attack
It was found that cephx authentication protocol did not verify ceph clients correctly and was vulnerable to replay attack. Any attacker having access to ceph cluster network who is able to sniff packets on network can use this vulnerability to authenticate with ceph service and perform actions allowed by ceph service. Ceph branches master, mimic, luminous and jewel are believed to be vulnerable.
It was found that cephx authentication protocol did not verify ceph clients correctly and was vulnerable to replay attack. Any attacker having access to the ceph cluster network who is also able to sniff packets on the network can use this vulnerability to authenticate with ceph service and perform actions allowed by ceph service.
Statement: Re
Debian
CVE-2018-1128: ceph - It was found that cephx authentication protocol did not verify ceph clients corr...
vendor_debian·2018·CVSS 7.5
CVE-2018-1128 [HIGH] CVE-2018-1128: ceph - It was found that cephx authentication protocol did not verify ceph clients corr...
It was found that cephx authentication protocol did not verify ceph clients correctly and was vulnerable to replay attack. Any attacker having access to ceph cluster network who is able to sniff packets on network can use this vulnerability to authenticate with ceph service and perform actions allowed by ceph service. Ceph branches master, mimic, luminous and jewel are believed to be vulnerable.
Scope: local
bookworm: resolved (fixed in 12.2.8+dfsg1-1)
bullseye: resolved (fixed in 12.2.8+dfsg1-1)
forky: resolved (fixed in 12.2.8+dfsg1-1)
sid: resolved (fixed in 12.2.8+dfsg1-1)
trixie: resolved (fixed in 12.2.8+dfsg1-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-25660 ceph: CEPHX_V2 replay attack protection lost
bugzilla·2020-10-22·CVSS 7.5
CVE-2020-25660 [HIGH] CVE-2020-25660 ceph: CEPHX_V2 replay attack protection lost
CVE-2020-25660 ceph: CEPHX_V2 replay attack protection lost
Ceph octopus lost CEPHX_V2 replay attack, and this was backported to nautilus in v14.2.5.This is very similar to a prior CVE, but we are requesting a new CVE because it only affects nautilus and later.
This flaw is very similar to CVE-2018-1128:
It was found that cephx authentication protocol did not verify ceph clients correctly and was vulnerable to replay attack. Any attacker having access to ceph cluster network who is able to sniff packets on network can use this vulnerability to authenticate with ceph service and perform actions allowed by ceph service.
Discussion:
https://github.com/ceph/ceph/pull/30524
https://github.com/ceph/ceph/pull/30523
These are the commits where the flaw was introduced.
---
Acknowledgments:
Bugzilla
CVE-2018-1000408 jenkins: Ephemeral user record creation
bugzilla·2018-10-25·CVSS 6.5
CVE-2018-1000408 [MEDIUM] CVE-2018-1000408 jenkins: Ephemeral user record creation
CVE-2018-1000408 jenkins: Ephemeral user record creation
By accessing a specific crafted URL on Jenkins instances using Jenkins' own user database, users without Overall/Read access could create ephemeral user records.
This behavior could be abused to create a large number of ephemeral user records in memory.
External References:
https://jenkins.io/security/advisory/2018-10-10/#SECURITY-1128
Discussion:
Created jenkins tracking bugs for this issue:
Affects: fedora-all [bug 1642894]
---
Jenkins security policy[0]:
"Any security advisory related updates to Jenkins core or the plugins we include in the OpenShift Jenkins master image will only occur in the v3.11 and v4.x branches of this repository.
We do support running the v3.11 version of the master image against older v3.x (as f
Bugzilla
CVE-2018-1128 ceph: cephx protocol is vulnerable to replay attack [fedora-all]
bugzilla·2018-07-09·CVSS 7.5
CVE-2018-1128 [HIGH] CVE-2018-1128 ceph: cephx protocol is vulnerable to replay attack [fedora-all]
CVE-2018-1128 ceph: cephx protocol is vulnerable to replay attack [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported version
Bugzilla
CVE-2018-1128 ceph: cephx protocol is vulnerable to replay attack
bugzilla·2018-05-08·CVSS 7.5
CVE-2018-1128 [HIGH] CVE-2018-1128 ceph: cephx protocol is vulnerable to replay attack
CVE-2018-1128 ceph: cephx protocol is vulnerable to replay attack
Service ticket issued using cephx to authenticate with a ceph service like Mon, OSD are vulnerable to replay attack. Ticket is sent with a nonce from client to service, service responds back to client with a mutation of nonce. This lets client verify that the service is what it says it is. Though this does not protect against a replay. If attacker is able to capture/sniff the exchange, attacker can replay the capture to authenticate with ceph service and perform actions only provided by the ceph service.
There are no known exploits against this, attacker has to be on the same network as of ceph cluster to be able to capture exchange.
Discussion:
upstream fix:
http://tracker.ceph.com/issues/24836
https://github.com/ceph/
http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00100.htmlhttp://tracker.ceph.com/issues/24836http://www.openwall.com/lists/oss-security/2020/11/17/3http://www.openwall.com/lists/oss-security/2020/11/17/4https://access.redhat.com/errata/RHSA-2018:2177https://access.redhat.com/errata/RHSA-2018:2179https://access.redhat.com/errata/RHSA-2018:2261https://access.redhat.com/errata/RHSA-2018:2274https://bugzilla.redhat.com/show_bug.cgi?id=1575866https://github.com/ceph/ceph/commit/5ead97120e07054d80623dada90a5cc764c28468https://lists.debian.org/debian-lts-announce/2019/03/msg00017.htmlhttps://www.debian.org/security/2018/dsa-4339http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00100.htmlhttp://tracker.ceph.com/issues/24836http://www.openwall.com/lists/oss-security/2020/11/17/3http://www.openwall.com/lists/oss-security/2020/11/17/4https://access.redhat.com/errata/RHSA-2018:2177https://access.redhat.com/errata/RHSA-2018:2179https://access.redhat.com/errata/RHSA-2018:2261https://access.redhat.com/errata/RHSA-2018:2274https://bugzilla.redhat.com/show_bug.cgi?id=1575866https://github.com/ceph/ceph/commit/5ead97120e07054d80623dada90a5cc764c28468https://lists.debian.org/debian-lts-announce/2019/03/msg00017.htmlhttps://www.debian.org/security/2018/dsa-4339
2018-07-10
Published