CVE-2018-14662
published 2019-01-15CVE-2018-14662: It was found Ceph versions before 13.2.4 that authenticated ceph users with read only permissions could steal dm-crypt encryption keys used in ceph disk…
PriorityP423medium5.7CVSS 3.1
AVAACLPRLUINSUCHINAN
EPSS
0.45%
36.2th percentile
It was found Ceph versions before 13.2.4 that authenticated ceph users with read only permissions could steal dm-crypt encryption keys used in ceph disk encryption.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | ceph | < ceph 12.2.11+dfsg1-1 (bookworm) | ceph 12.2.11+dfsg1-1 (bookworm) |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| opensuse | leap | — | — |
| redhat | ceph | < 13.2.4 | 13.2.4 |
| redhat | ceph | >= 0 < 12.2.11+dfsg1-1 | 12.2.11+dfsg1-1 |
| redhat | ceph | >= 0 < 12.2.11+dfsg1-1 | 12.2.11+dfsg1-1 |
| redhat | ceph | >= 0 < 12.2.11+dfsg1-1 | 12.2.11+dfsg1-1 |
| redhat | ceph | >= 0 < 12.2.11+dfsg1-1 | 12.2.11+dfsg1-1 |
| redhat | ceph | >= 0 < 10.2.11-0ubuntu0.16.04.2 | 10.2.11-0ubuntu0.16.04.2 |
| redhat | ceph | >= 0 < 0.80.11-0ubuntu1.14.04.4+esm3 | 0.80.11-0ubuntu1.14.04.4+esm3 |
| redhat | ceph | >= 0 < 10.2.11-0ubuntu0.16.04.3+esm2 | 10.2.11-0ubuntu0.16.04.3+esm2 |
| redhat | ceph_storage | — | — |
| redhat | ceph_storage | — | — |
| redhat | enterprise_linux_server | — | — |
CVSS provenance
nvdv3.15.7MEDIUMCVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv3.03.5LOWCVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvdv2.02.7LOWAV:A/AC:L/Au:S/C:P/I:N/A:N
osv5.7MEDIUM
vendor_debian5.7MEDIUM
vendor_redhat5.7MEDIUM
vendor_ubuntu5.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Ceph vulnerabilities
vendor_ubuntu·2025-08-20·CVSS 5.7
CVE-2021-3524 [MEDIUM] Ceph vulnerabilities
Title: Ceph vulnerabilities
Summary: Several security issues were fixed in Ceph.
It was discovered that Ceph incorrectly handled read-only permissions. An
authenticated attacker could use this issue to obtain dm-crypt encryption
keys. This issue only affected Ubuntu 14.04 LTS. (CVE-2018-14662)
Sergey Bobrov discovered that Ceph’s RadosGW (Ceph Object Gateway) allowed
the injection of HTTP headers in responses to CORS requests. An attacker
could possibly use this issue to compromise system integrity. This issue
only
affected Ubuntu 16.04 LTS. (CVE-2021-3524)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Ceph vulnerabilities
vendor_ubuntu·2019-06-25·CVSS 5.7
CVE-2018-14662 [MEDIUM] Ceph vulnerabilities
Title: Ceph vulnerabilities
Summary: Several security issues were fixed in Ceph.
It was discovered that Ceph incorrectly handled read only permissions. An
authenticated attacker could use this issue to obtain dm-crypt encryption
keys. This issue only affected Ubuntu 16.04 LTS. (CVE-2018-14662)
It was discovered that Ceph incorrectly handled certain OMAPs holding
bucket indices. An authenticated attacker could possibly use this issue to
cause a denial of service. This issue only affected Ubuntu 16.04 LTS.
(CVE-2018-16846)
It was discovered that Ceph incorrectly sanitized certain debug logs. A
local attacker could possibly use this issue to obtain encryption key
information. This issue was only addressed in Ubuntu 18.10 and Ubuntu
19.04. (CVE-2018-16889)
It was discovered that Ceph inco
Red Hat
ceph: authenticated user with read only permissions can steal dm-crypt / LUKS key
vendor_redhat·2019-01-07·CVSS 5.7
CVE-2018-14662 [MEDIUM] CWE-285 ceph: authenticated user with read only permissions can steal dm-crypt / LUKS key
ceph: authenticated user with read only permissions can steal dm-crypt / LUKS key
It was found Ceph versions before 13.2.4 that authenticated ceph users with read only permissions could steal dm-crypt encryption keys used in ceph disk encryption.
It was found that authenticated ceph user with read only permissions could steal dm-crypt encryption keys used in ceph disk encryption.
Package: ceph (Red Hat Ceph Storage 2) - Affected
Package: ceph-common (Red Hat Enterprise Linux 7) - Not affected
Package: ceph (Red Hat Enterprise Linux 8) - Not affected
Debian
CVE-2018-14662: ceph - It was found Ceph versions before 13.2.4 that authenticated ceph users with read...
vendor_debian·2018·CVSS 5.7
CVE-2018-14662 [MEDIUM] CVE-2018-14662: ceph - It was found Ceph versions before 13.2.4 that authenticated ceph users with read...
It was found Ceph versions before 13.2.4 that authenticated ceph users with read only permissions could steal dm-crypt encryption keys used in ceph disk encryption.
Scope: local
bookworm: resolved (fixed in 12.2.11+dfsg1-1)
bullseye: resolved (fixed in 12.2.11+dfsg1-1)
forky: resolved (fixed in 12.2.11+dfsg1-1)
sid: resolved (fixed in 12.2.11+dfsg1-1)
trixie: resolved (fixed in 12.2.11+dfsg1-1)
OSV
ceph vulnerabilities
osv·2025-08-20·CVSS 5.7
CVE-2018-14662 [MEDIUM] ceph vulnerabilities
ceph vulnerabilities
It was discovered that Ceph incorrectly handled read-only permissions. An
authenticated attacker could use this issue to obtain dm-crypt encryption
keys. This issue only affected Ubuntu 14.04 LTS. (CVE-2018-14662)
Sergey Bobrov discovered that Ceph’s RadosGW (Ceph Object Gateway) allowed
the injection of HTTP headers in responses to CORS requests. An attacker
could possibly use this issue to compromise system integrity. This issue
only
affected Ubuntu 16.04 LTS. (CVE-2021-3524)
GHSA
GHSA-w2x2-w9fr-cf6g: It was found Ceph versions before 13
ghsa_unreviewed·2022-05-13
CVE-2018-14662 [MEDIUM] CWE-285 GHSA-w2x2-w9fr-cf6g: It was found Ceph versions before 13
It was found Ceph versions before 13.2.4 that authenticated ceph users with read only permissions could steal dm-crypt encryption keys used in ceph disk encryption.
OSV
ceph vulnerabilities
osv·2019-06-25·CVSS 5.7
CVE-2018-14662 [MEDIUM] ceph vulnerabilities
ceph vulnerabilities
It was discovered that Ceph incorrectly handled read only permissions. An
authenticated attacker could use this issue to obtain dm-crypt encryption
keys. This issue only affected Ubuntu 16.04 LTS. (CVE-2018-14662)
It was discovered that Ceph incorrectly handled certain OMAPs holding
bucket indices. An authenticated attacker could possibly use this issue to
cause a denial of service. This issue only affected Ubuntu 16.04 LTS.
(CVE-2018-16846)
It was discovered that Ceph incorrectly sanitized certain debug logs. A
local attacker could possibly use this issue to obtain encryption key
information. This issue was only addressed in Ubuntu 18.10 and Ubuntu
19.04. (CVE-2018-16889)
It was discovered that Ceph incorrectly handled certain civetweb requests.
A remote attacker
OSV
CVE-2018-14662: It was found Ceph versions before 13
osv·2019-01-15·CVSS 5.7
CVE-2018-14662 [MEDIUM] CVE-2018-14662: It was found Ceph versions before 13
It was found Ceph versions before 13.2.4 that authenticated ceph users with read only permissions could steal dm-crypt encryption keys used in ceph disk encryption.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-14662 ceph: authenticated user with read only permissions can steal dm-crypt / LUKS key [fedora-all]
bugzilla·2019-01-14·CVSS 5.7
CVE-2018-14662 [MEDIUM] CVE-2018-14662 ceph: authenticated user with read only permissions can steal dm-crypt / LUKS key [fedora-all]
CVE-2018-14662 ceph: authenticated user with read only permissions can steal dm-crypt / LUKS key [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue aff
Bugzilla
CVE-2018-14662 ceph: authenticated user with read only permissions can steal dm-crypt / LUKS key
bugzilla·2018-10-09·CVSS 5.7
CVE-2018-14662 [MEDIUM] CVE-2018-14662 ceph: authenticated user with read only permissions can steal dm-crypt / LUKS key
CVE-2018-14662 ceph: authenticated user with read only permissions can steal dm-crypt / LUKS key
The Ceph documentation states that clients should use "allow r" mon caps[1][2][3], which will grant full read access to all config-keys stored in the monitor -- including the LUKS encryption keys for OSD.
This is in contrast to the original dm-crypt key management feature[4], which indicates that these keys should be restricted to only the lockbox user.
Upstream Documentation:
[1] http://docs.ceph.com/docs/master/cephfs/client-auth/
[2] http://docs.ceph.com/docs/emperor/rados/operations/authentication/#add-a-key
[3] http://docs.ceph.com/docs/master/rados/operations/user-management/#add-a-user
[4] https://tracker.ceph.com/projects/ceph/wiki/Osd_-_simple_ceph-mon_dm-crypt_key_management
Di
http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00100.htmlhttps://access.redhat.com/errata/RHSA-2019:2538https://access.redhat.com/errata/RHSA-2019:2541https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14662https://ceph.com/releases/13-2-4-mimic-releasedhttps://lists.debian.org/debian-lts-announce/2019/03/msg00002.htmlhttps://lists.debian.org/debian-lts-announce/2021/08/msg00013.htmlhttps://usn.ubuntu.com/4035-1/http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00100.htmlhttps://access.redhat.com/errata/RHSA-2019:2538https://access.redhat.com/errata/RHSA-2019:2541https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14662https://ceph.com/releases/13-2-4-mimic-releasedhttps://lists.debian.org/debian-lts-announce/2019/03/msg00002.htmlhttps://lists.debian.org/debian-lts-announce/2021/08/msg00013.htmlhttps://usn.ubuntu.com/4035-1/
2019-01-15
Published