CVE-2020-1759
published 2020-04-13CVE-2020-1759: A vulnerability was found in Red Hat Ceph Storage 4 and Red Hat Openshift Container Storage 4.2 where, A nonce reuse vulnerability was discovered in the secure…
PriorityP432medium6.8CVSS 3.1
AVNACHPRNUIRSUCHIHAN
EPSS
1.58%
72.9th percentile
A vulnerability was found in Red Hat Ceph Storage 4 and Red Hat Openshift Container Storage 4.2 where, A nonce reuse vulnerability was discovered in the secure mode of the messenger v2 protocol, which can allow an attacker to forge auth tags and potentially manipulate the data by leveraging the reuse of a nonce in a session. Messages encrypted using a reused nonce value are susceptible to serious confidentiality and integrity attacks.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ceph | < ceph 14.2.9-1 (bookworm) | ceph 14.2.9-1 (bookworm) |
| fedoraproject | fedora | — | — |
| linuxfoundation | ceph | < 14.2.21 | 14.2.21 |
| redhat | ceph_storage | — | — |
| redhat | openshift | — | — |
| redhat | openstack | — | — |
| the_ceph_project | ceph | — | — |
| the_ceph_project | ceph | — | — |
| the_ceph_project | ceph | >= 0 < 14.2.9-1 | 14.2.9-1 |
| the_ceph_project | ceph | >= 0 < 14.2.9-1 | 14.2.9-1 |
| the_ceph_project | ceph | >= 0 < 14.2.9-1 | 14.2.9-1 |
| the_ceph_project | ceph | >= 0 < 14.2.9-1 | 14.2.9-1 |
CVSS provenance
nvdv3.16.8MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
osv6.8MEDIUM
vendor_debian6.4MEDIUM
vendor_redhat6.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-hcpq-vw4g-3vmh: A vulnerability was found in Red Hat Ceph Storage 4 and Red Hat Openshift Container Storage 4
ghsa_unreviewed·2022-05-24
CVE-2020-1759 [MEDIUM] CWE-323 GHSA-hcpq-vw4g-3vmh: A vulnerability was found in Red Hat Ceph Storage 4 and Red Hat Openshift Container Storage 4
A vulnerability was found in Red Hat Ceph Storage 4 and Red Hat Openshift Container Storage 4.2 where, A nonce reuse vulnerability was discovered in the secure mode of the messenger v2 protocol, which can allow an attacker to forge auth tags and potentially manipulate the data by leveraging the reuse of a nonce in a session. Messages encrypted using a reused nonce value are susceptible to serious confidentiality and integrity attacks.
OSV
CVE-2020-1759: A vulnerability was found in Red Hat Ceph Storage 4 and Red Hat Openshift Container Storage 4
osv·2020-04-13·CVSS 6.8
CVE-2020-1759 [MEDIUM] CVE-2020-1759: A vulnerability was found in Red Hat Ceph Storage 4 and Red Hat Openshift Container Storage 4
A vulnerability was found in Red Hat Ceph Storage 4 and Red Hat Openshift Container Storage 4.2 where, A nonce reuse vulnerability was discovered in the secure mode of the messenger v2 protocol, which can allow an attacker to forge auth tags and potentially manipulate the data by leveraging the reuse of a nonce in a session. Messages encrypted using a reused nonce value are susceptible to serious confidentiality and integrity attacks.
Red Hat
ceph: secure mode of msgr2 breaks both confidentiality and integrity aspects for long-lived sessions
vendor_redhat·2020-04-06·CVSS 6.4
CVE-2020-1759 [MEDIUM] CWE-323 ceph: secure mode of msgr2 breaks both confidentiality and integrity aspects for long-lived sessions
ceph: secure mode of msgr2 breaks both confidentiality and integrity aspects for long-lived sessions
A vulnerability was found in Red Hat Ceph Storage 4 and Red Hat Openshift Container Storage 4.2 where, A nonce reuse vulnerability was discovered in the secure mode of the messenger v2 protocol, which can allow an attacker to forge auth tags and potentially manipulate the data by leveraging the reuse of a nonce in a session. Messages encrypted using a reused nonce value are susceptible to serious confidentiality and integrity attacks.
A nonce reuse vulnerability was discovered in the secure mode of the messenger v2 protocol, which can allow an attacker to forge auth tags and potentially manipulate the data by leveraging the reuse of a nonce in a session. Messages encrypted using a reused
Debian
CVE-2020-1759: ceph - A vulnerability was found in Red Hat Ceph Storage 4 and Red Hat Openshift Contai...
vendor_debian·2020·CVSS 6.4
CVE-2020-1759 [MEDIUM] CVE-2020-1759: ceph - A vulnerability was found in Red Hat Ceph Storage 4 and Red Hat Openshift Contai...
A vulnerability was found in Red Hat Ceph Storage 4 and Red Hat Openshift Container Storage 4.2 where, A nonce reuse vulnerability was discovered in the secure mode of the messenger v2 protocol, which can allow an attacker to forge auth tags and potentially manipulate the data by leveraging the reuse of a nonce in a session. Messages encrypted using a reused nonce value are susceptible to serious confidentiality and integrity attacks.
Scope: local
bookworm: resolved (fixed in 14.2.9-1)
bullseye: resolved (fixed in 14.2.9-1)
forky: resolved (fixed in 14.2.9-1)
sid: resolved (fixed in 14.2.9-1)
trixie: resolved (fixed in 14.2.9-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-1759 ceph: secure mode of msgr2 breaks both confidentiality and integrity aspects for long-lived sessions [fedora-all]
bugzilla·2020-04-07·CVSS 6.4
CVE-2020-1759 [MEDIUM] CVE-2020-1759 ceph: secure mode of msgr2 breaks both confidentiality and integrity aspects for long-lived sessions [fedora-all]
CVE-2020-1759 ceph: secure mode of msgr2 breaks both confidentiality and integrity aspects for long-lived sessions [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NO
Bugzilla
CVE-2020-1759 ceph: secure mode of msgr2 breaks both confidentiality and integrity aspects for long-lived sessions
bugzilla·2020-03-09·CVSS 6.4
CVE-2020-1759 [MEDIUM] CVE-2020-1759 ceph: secure mode of msgr2 breaks both confidentiality and integrity aspects for long-lived sessions
CVE-2020-1759 ceph: secure mode of msgr2 breaks both confidentiality and integrity aspects for long-lived sessions
A flaw was found, where there's a problem with the secure mode of msgr2, which breaks confidentiality and integrity aspects for long-lived sessions.
Discussion:
Acknowledgments:
Name: Ilya Dryomov (Red Hat)
---
Created ceph tracking bugs for this issue:
Affects: fedora-all [bug 1821586]
---
Upstream Patches:
https://github.com/ceph/ceph-ci/commit/84d2e215969cde830b086d11544aeb3666614211
https://github.com/ceph/ceph-ci/commit/659ec7dc6e30fe961832f813da007f49e603a33d
The patches are currently available from ceph.git clone(ceph-ci) and will be pushed to active releases soon.
---
Patches are merged in upstream Octopus version 15.2.1 via PR https://github.com/ceph/ceph
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1759https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/P3A2UFR5IUIEXJUCF64GQ5OVLCZGODXE/https://security.gentoo.org/glsa/202105-39https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1759https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/P3A2UFR5IUIEXJUCF64GQ5OVLCZGODXE/https://security.gentoo.org/glsa/202105-39
2020-04-13
Published