Severity
6.5MEDIUM
EPSS
0.3%
top 44.18%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 10
Latest updateMay 14

Description

A flaw was found in the way signature calculation was handled by cephx authentication protocol. An attacker having access to ceph cluster network who is able to alter the message payload was able to bypass signature checks done by cephx protocol. Ceph branches master, mimic, luminous and jewel are believed to be vulnerable.

CVSS vector

CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages11 packages

Debianceph< 12.2.8+dfsg1-1+3
NVDceph/ceph22 versions+21
CVEListV5red_hat,_inc./cephall versions in branches master, mimic, luminous and jewel
NVDredhat/ceph_storage1.3, 3+1

Also affects: Debian Linux 8.0, 9.0, Enterprise Linux 7.0

Patches

🔴Vulnerability Details

4
GHSA
GHSA-7qc9-w55v-w7p3: A flaw was found in the way signature calculation was handled by cephx authentication protocol2022-05-14
Kernel
libceph: implement CEPHX_V2 calculation mode2018-07-27
CVEList
CVE-2018-1129: A flaw was found in the way signature calculation was handled by cephx authentication protocol2018-07-10
OSV
CVE-2018-1129: A flaw was found in the way signature calculation was handled by cephx authentication protocol2018-07-10

📋Vendor Advisories

3
Microsoft
A flaw was found in the way signature calculation was handled by cephx authentication protocol. An attacker having access to ceph cluster network who is able to alter the message payload was able to b2018-07-10
Red Hat
ceph: cephx uses weak signatures2018-07-09
Debian
CVE-2018-1129: ceph - A flaw was found in the way signature calculation was handled by cephx authentic...2018

💬Community

3
Bugzilla
CVE-2018-1000407 jenkins: Reflected XSS vulnerability2018-10-25
Bugzilla
CVE-2018-1129 ceph: cephx uses weak signatures [fedora-all]2018-07-09
Bugzilla
CVE-2018-1129 ceph: cephx uses weak signatures2018-05-08
CVE-2018-1129 (MEDIUM CVSS 6.5) | A flaw was found in the way signatu | cvebase.io