CVE-2018-1129
published 2018-07-10CVE-2018-1129: A flaw was found in the way signature calculation was handled by cephx authentication protocol. An attacker having access to ceph cluster network who is able…
PriorityP432medium6.5CVSS 3.0
AVAACLPRNUINSUCNIHAN
EPSS
1.90%
77.4th percentile
A flaw was found in the way signature calculation was handled by cephx authentication protocol. An attacker having access to ceph cluster network who is able to alter the message payload was able to bypass signature checks done by cephx protocol. Ceph branches master, mimic, luminous and jewel are believed to be vulnerable.
Affected
50 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ceph | ceph | — | — |
| ceph | ceph | — | — |
| ceph | ceph | — | — |
| ceph | ceph | — | — |
| ceph | ceph | — | — |
| ceph | ceph | — | — |
| ceph | ceph | — | — |
| ceph | ceph | — | — |
| ceph | ceph | — | — |
| ceph | ceph | — | — |
| ceph | ceph | — | — |
| ceph | ceph | — | — |
| ceph | ceph | — | — |
| ceph | ceph | — | — |
| ceph | ceph | — | — |
| ceph | ceph | — | — |
| ceph | ceph | — | — |
| ceph | ceph | — | — |
| ceph | ceph | — | — |
| ceph | ceph | — | — |
| ceph | ceph | — | — |
| ceph | ceph | — | — |
| debian | ceph | < ceph 12.2.8+dfsg1-1 (bookworm) | ceph 12.2.8+dfsg1-1 (bookworm) |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.03.3LOWAV:A/AC:L/Au:N/C:N/I:P/A:N
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_msrc6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7qc9-w55v-w7p3: A flaw was found in the way signature calculation was handled by cephx authentication protocol
ghsa_unreviewed·2022-05-14
CVE-2018-1129 [MEDIUM] CWE-287 GHSA-7qc9-w55v-w7p3: A flaw was found in the way signature calculation was handled by cephx authentication protocol
A flaw was found in the way signature calculation was handled by cephx authentication protocol. An attacker having access to ceph cluster network who is able to alter the message payload was able to bypass signature checks done by cephx protocol. Ceph branches master, mimic, luminous and jewel are believed to be vulnerable.
Kernel
libceph: implement CEPHX_V2 calculation mode
kernel_security·2018-07-27·CVSS 6.5
CVE-2018-1129 [MEDIUM] libceph: implement CEPHX_V2 calculation mode
libceph: implement CEPHX_V2 calculation mode
Derive the signature from the entire buffer (both AES cipher blocks)
instead of using just the first half of the first block, leaving out
data_crc entirely.
This addresses CVE-2018-1129.
Link: http://tracker.ceph.com/issues/24837
Signed-off-by: Ilya Dryomov
Reviewed-by: Sage Weil
OSV
CVE-2018-1129: A flaw was found in the way signature calculation was handled by cephx authentication protocol
osv·2018-07-10·CVSS 6.5
CVE-2018-1129 [MEDIUM] CVE-2018-1129: A flaw was found in the way signature calculation was handled by cephx authentication protocol
A flaw was found in the way signature calculation was handled by cephx authentication protocol. An attacker having access to ceph cluster network who is able to alter the message payload was able to bypass signature checks done by cephx protocol. Ceph branches master, mimic, luminous and jewel are believed to be vulnerable.
Microsoft
A flaw was found in the way signature calculation was handled by cephx authentication protocol. An attacker having access to ceph cluster network who is able to alter the message payload was able to b
vendor_msrc·2018-07-10·CVSS 6.5
CVE-2018-1129 [MEDIUM] CWE-287 A flaw was found in the way signature calculation was handled by cephx authentication protocol. An attacker having access to ceph cluster network who is able to alter the message payload was able to b
A flaw was found in the way signature calculation was handled by cephx authentication protocol. An attacker having access to ceph cluster network who is able to alter the message payload was able to bypass signature checks done by cephx protocol. Ceph branches master mimic luminous and jewel are believed to be vulnerable.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX i
Red Hat
ceph: cephx uses weak signatures
vendor_redhat·2018-07-09·CVSS 6.5
CVE-2018-1129 [MEDIUM] CWE-284 ceph: cephx uses weak signatures
ceph: cephx uses weak signatures
A flaw was found in the way signature calculation was handled by cephx authentication protocol. An attacker having access to ceph cluster network who is able to alter the message payload was able to bypass signature checks done by cephx protocol. Ceph branches master, mimic, luminous and jewel are believed to be vulnerable.
A flaw was found in the way signature calculation was handled by cephx authentication protocol. An attacker having access to ceph cluster network, who is able to alter the message payload, was able to bypass signature checks done by cephx protocol.
Package: ceph (Red Hat Ceph Storage 1.3) - Will not fix
Package: ceph-common (Red Hat Enterprise Linux 7) - Will not fix
Package: ceph (Red Hat Enterprise Linux 8) - Not affected
Debian
CVE-2018-1129: ceph - A flaw was found in the way signature calculation was handled by cephx authentic...
vendor_debian·2018·CVSS 6.5
CVE-2018-1129 [MEDIUM] CVE-2018-1129: ceph - A flaw was found in the way signature calculation was handled by cephx authentic...
A flaw was found in the way signature calculation was handled by cephx authentication protocol. An attacker having access to ceph cluster network who is able to alter the message payload was able to bypass signature checks done by cephx protocol. Ceph branches master, mimic, luminous and jewel are believed to be vulnerable.
Scope: local
bookworm: resolved (fixed in 12.2.8+dfsg1-1)
bullseye: resolved (fixed in 12.2.8+dfsg1-1)
forky: resolved (fixed in 12.2.8+dfsg1-1)
sid: resolved (fixed in 12.2.8+dfsg1-1)
trixie: resolved (fixed in 12.2.8+dfsg1-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-1000407 jenkins: Reflected XSS vulnerability
bugzilla·2018-10-25·CVSS 6.1
CVE-2018-1000407 [MEDIUM] CVE-2018-1000407 jenkins: Reflected XSS vulnerability
CVE-2018-1000407 jenkins: Reflected XSS vulnerability
The wrapper query parameter for the XML variant of the Jenkins remote API did not validate the specified tag name. This resulted in a reflected cross-site scripting vulnerability.
External References:
https://jenkins.io/security/advisory/2018-10-10/#SECURITY-1129
Discussion:
Created jenkins tracking bugs for this issue:
Affects: fedora-all [bug 1642894]
---
Jenkins security policy[0]:
"Any security advisory related updates to Jenkins core or the plugins we include in the OpenShift Jenkins master image will only occur in the v3.11 and v4.x branches of this repository.
We do support running the v3.11 version of the master image against older v3.x (as far back as v3.4) OpenShift clusters if you want to pick up Jenkins security ad
Bugzilla
CVE-2018-1129 ceph: cephx uses weak signatures [fedora-all]
bugzilla·2018-07-09·CVSS 6.5
CVE-2018-1129 [MEDIUM] CVE-2018-1129 ceph: cephx uses weak signatures [fedora-all]
CVE-2018-1129 ceph: cephx uses weak signatures [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. While
Bugzilla
CVE-2018-1129 ceph: cephx uses weak signatures
bugzilla·2018-05-08·CVSS 6.5
CVE-2018-1129 [MEDIUM] CVE-2018-1129 ceph: cephx uses weak signatures
CVE-2018-1129 ceph: cephx uses weak signatures
A flaw was found in the way signature calculation is handled by cephx protocol. The signature calculation is encrypting a 29 byte struct with 16-byte block AES cipher, and then using the first 8 bytes of the result as signature. This only covers first (16 by tes) cipher block, data_crc falls on second block.There are no known exploits against this, If attacker can alter the message payload any changes in data_crc will not be noticed or checked by signature check.
Discussion:
upstream fix:
http://tracker.ceph.com/issues/24837
https://github.com/ceph/ceph/commit/8f396cf35a3826044b089141667a196454c0a587
---
Created ceph tracking bugs for this issue:
Affects: fedora-all [bug 1599408]
---
This issue has been addressed in the following prod
http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00100.htmlhttp://packetstormsecurity.com/files/154245/Kernel-Live-Patch-Security-Notice-LSN-0054-1.htmlhttp://tracker.ceph.com/issues/24837https://access.redhat.com/errata/RHSA-2018:2177https://access.redhat.com/errata/RHSA-2018:2179https://access.redhat.com/errata/RHSA-2018:2261https://access.redhat.com/errata/RHSA-2018:2274https://bugzilla.redhat.com/show_bug.cgi?id=1576057https://github.com/ceph/ceph/commit/8f396cf35a3826044b089141667a196454c0a587https://lists.debian.org/debian-lts-announce/2019/03/msg00017.htmlhttps://www.debian.org/security/2018/dsa-4339http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00100.htmlhttp://packetstormsecurity.com/files/154245/Kernel-Live-Patch-Security-Notice-LSN-0054-1.htmlhttp://tracker.ceph.com/issues/24837https://access.redhat.com/errata/RHSA-2018:2177https://access.redhat.com/errata/RHSA-2018:2179https://access.redhat.com/errata/RHSA-2018:2261https://access.redhat.com/errata/RHSA-2018:2274https://bugzilla.redhat.com/show_bug.cgi?id=1576057https://github.com/ceph/ceph/commit/8f396cf35a3826044b089141667a196454c0a587https://lists.debian.org/debian-lts-announce/2019/03/msg00017.htmlhttps://www.debian.org/security/2018/dsa-4339
2018-07-10
Published