cbcvebase.
CVE-2018-1129
published 2018-07-10

CVE-2018-1129: A flaw was found in the way signature calculation was handled by cephx authentication protocol. An attacker having access to ceph cluster network who is able…

PriorityP432medium6.5CVSS 3.0
AVAACLPRNUINSUCNIHAN
EPSS
1.90%
77.4th percentile
A flaw was found in the way signature calculation was handled by cephx authentication protocol. An attacker having access to ceph cluster network who is able to alter the message payload was able to bypass signature checks done by cephx protocol. Ceph branches master, mimic, luminous and jewel are believed to be vulnerable.

Affected

50 ranges· showing 25
VendorProductVersion rangeFixed in
cephceph
cephceph
cephceph
cephceph
cephceph
cephceph
cephceph
cephceph
cephceph
cephceph
cephceph
cephceph
cephceph
cephceph
cephceph
cephceph
cephceph
cephceph
cephceph
cephceph
cephceph
cephceph
debianceph< ceph 12.2.8+dfsg1-1 (bookworm)ceph 12.2.8+dfsg1-1 (bookworm)
debiandebian_linux
debiandebian_linux

CVSS provenance

nvdv3.06.5MEDIUMCVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.03.3LOWAV:A/AC:L/Au:N/C:N/I:P/A:N
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_msrc6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.