CVE-2018-16846
published 2019-01-15CVE-2018-16846: It was found in Ceph versions before 13.2.4 that authenticated ceph RGW users can cause a denial of service against OMAPs holding bucket indices.
PriorityP429medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
2.14%
80.0th percentile
It was found in Ceph versions before 13.2.4 that authenticated ceph RGW users can cause a denial of service against OMAPs holding bucket indices.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | ceph | < ceph 12.2.11+dfsg1-1 (bookworm) | ceph 12.2.11+dfsg1-1 (bookworm) |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| opensuse | leap | — | — |
| redhat | ceph | < 13.2.4 | 13.2.4 |
| redhat | ceph | >= 0 < 12.2.11+dfsg1-1 | 12.2.11+dfsg1-1 |
| redhat | ceph | >= 0 < 12.2.11+dfsg1-1 | 12.2.11+dfsg1-1 |
| redhat | ceph | >= 0 < 12.2.11+dfsg1-1 | 12.2.11+dfsg1-1 |
| redhat | ceph | >= 0 < 12.2.11+dfsg1-1 | 12.2.11+dfsg1-1 |
| redhat | ceph | >= 0 < 10.2.11-0ubuntu0.16.04.2 | 10.2.11-0ubuntu0.16.04.2 |
| redhat | ceph_storage | — | — |
| redhat | ceph_storage | — | — |
| redhat | enterprise_linux_server | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
vendor_ubuntu5.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-77fq-6x6c-cq7q: It was found in Ceph versions before 13
ghsa_unreviewed·2022-05-13
CVE-2018-16846 [MEDIUM] CWE-770 GHSA-77fq-6x6c-cq7q: It was found in Ceph versions before 13
It was found in Ceph versions before 13.2.4 that authenticated ceph RGW users can cause a denial of service against OMAPs holding bucket indices.
OSV
ceph vulnerabilities
osv·2019-06-25·CVSS 5.7
CVE-2018-14662 [MEDIUM] ceph vulnerabilities
ceph vulnerabilities
It was discovered that Ceph incorrectly handled read only permissions. An
authenticated attacker could use this issue to obtain dm-crypt encryption
keys. This issue only affected Ubuntu 16.04 LTS. (CVE-2018-14662)
It was discovered that Ceph incorrectly handled certain OMAPs holding
bucket indices. An authenticated attacker could possibly use this issue to
cause a denial of service. This issue only affected Ubuntu 16.04 LTS.
(CVE-2018-16846)
It was discovered that Ceph incorrectly sanitized certain debug logs. A
local attacker could possibly use this issue to obtain encryption key
information. This issue was only addressed in Ubuntu 18.10 and Ubuntu
19.04. (CVE-2018-16889)
It was discovered that Ceph incorrectly handled certain civetweb requests.
A remote attacker
OSV
CVE-2018-16846: It was found in Ceph versions before 13
osv·2019-01-15·CVSS 6.5
CVE-2018-16846 [MEDIUM] CVE-2018-16846: It was found in Ceph versions before 13
It was found in Ceph versions before 13.2.4 that authenticated ceph RGW users can cause a denial of service against OMAPs holding bucket indices.
Ubuntu
Ceph vulnerabilities
vendor_ubuntu·2019-06-25·CVSS 5.7
CVE-2018-14662 [MEDIUM] Ceph vulnerabilities
Title: Ceph vulnerabilities
Summary: Several security issues were fixed in Ceph.
It was discovered that Ceph incorrectly handled read only permissions. An
authenticated attacker could use this issue to obtain dm-crypt encryption
keys. This issue only affected Ubuntu 16.04 LTS. (CVE-2018-14662)
It was discovered that Ceph incorrectly handled certain OMAPs holding
bucket indices. An authenticated attacker could possibly use this issue to
cause a denial of service. This issue only affected Ubuntu 16.04 LTS.
(CVE-2018-16846)
It was discovered that Ceph incorrectly sanitized certain debug logs. A
local attacker could possibly use this issue to obtain encryption key
information. This issue was only addressed in Ubuntu 18.10 and Ubuntu
19.04. (CVE-2018-16889)
It was discovered that Ceph inco
Red Hat
ceph: ListBucket max-keys has no defined limit in the RGW codebase
vendor_redhat·2019-01-07·CVSS 6.5
CVE-2018-16846 [MEDIUM] CWE-770 ceph: ListBucket max-keys has no defined limit in the RGW codebase
ceph: ListBucket max-keys has no defined limit in the RGW codebase
It was found in Ceph versions before 13.2.4 that authenticated ceph RGW users can cause a denial of service against OMAPs holding bucket indices.
A flaw was found in the way the ListBucket function max-keys has no defined limit in the RGW codebase. An authenticated ceph RGW user can cause a denial of service attack against OMAPs holding bucked indices.
Package: ceph (Red Hat Ceph Storage 2) - Will not fix
Package: ceph-common (Red Hat Enterprise Linux 7) - Not affected
Package: ceph (Red Hat Enterprise Linux 8) - Not affected
Package: redhat-virtualization-host (Red Hat Virtualization 4) - Not affected
Debian
CVE-2018-16846: ceph - It was found in Ceph versions before 13.2.4 that authenticated ceph RGW users ca...
vendor_debian·2018·CVSS 6.5
CVE-2018-16846 [MEDIUM] CVE-2018-16846: ceph - It was found in Ceph versions before 13.2.4 that authenticated ceph RGW users ca...
It was found in Ceph versions before 13.2.4 that authenticated ceph RGW users can cause a denial of service against OMAPs holding bucket indices.
Scope: local
bookworm: resolved (fixed in 12.2.11+dfsg1-1)
bullseye: resolved (fixed in 12.2.11+dfsg1-1)
forky: resolved (fixed in 12.2.11+dfsg1-1)
sid: resolved (fixed in 12.2.11+dfsg1-1)
trixie: resolved (fixed in 12.2.11+dfsg1-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-16846 ceph: ListBucket max-keys has no defined limit in the RGW codebase [fedora-all]
bugzilla·2019-01-14·CVSS 6.5
CVE-2018-16846 [MEDIUM] CVE-2018-16846 ceph: ListBucket max-keys has no defined limit in the RGW codebase [fedora-all]
CVE-2018-16846 ceph: ListBucket max-keys has no defined limit in the RGW codebase [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple s
Bugzilla
CVE-2018-16846 ceph: ListBucket max-keys has no defined limit in the RGW codebase
bugzilla·2018-10-30·CVSS 6.5
CVE-2018-16846 [MEDIUM] CVE-2018-16846 ceph: ListBucket max-keys has no defined limit in the RGW codebase
CVE-2018-16846 ceph: ListBucket max-keys has no defined limit in the RGW codebase
RGW S3 listing operations provided a way for authenticated users to cause a denial of service against OMAPs holding bucket indices.
References:
http://tracker.ceph.com/issues/35994
Discussion:
External References:
https://ceph.com/releases/13-2-4-mimic-released/
---
Created ceph tracking bugs for this issue:
Affects: fedora-all [bug 1665973]
---
upstream fix
https://github.com/ceph/ceph/commit/ab29bed2fc9f961fe895de1086a8208e21ddaddc
---
This issue has been addressed in the following products:
Red Hat Ceph Storage 3.3
Via RHSA-2019:2538 https://access.redhat.com/errata/RHSA-2019:2538
---
This issue has been addressed in the following products:
Red Hat Ceph Storage 3 for Red Hat Enterprise L
http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00100.htmlhttps://access.redhat.com/errata/RHSA-2019:2538https://access.redhat.com/errata/RHSA-2019:2541https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16846https://ceph.com/releases/13-2-4-mimic-released/https://lists.debian.org/debian-lts-announce/2019/03/msg00002.htmlhttps://lists.debian.org/debian-lts-announce/2021/08/msg00013.htmlhttps://usn.ubuntu.com/4035-1/http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00100.htmlhttps://access.redhat.com/errata/RHSA-2019:2538https://access.redhat.com/errata/RHSA-2019:2541https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16846https://ceph.com/releases/13-2-4-mimic-released/https://lists.debian.org/debian-lts-announce/2019/03/msg00002.htmlhttps://lists.debian.org/debian-lts-announce/2021/08/msg00013.htmlhttps://usn.ubuntu.com/4035-1/
2019-01-15
Published