CVE-2020-1759

CWE-323CWE-3308 documents7 sources
Severity
6.8MEDIUM
EPSS
0.4%
top 38.56%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 13
Latest updateMay 24

Description

A vulnerability was found in Red Hat Ceph Storage 4 and Red Hat Openshift Container Storage 4.2 where, A nonce reuse vulnerability was discovered in the secure mode of the messenger v2 protocol, which can allow an attacker to forge auth tags and potentially manipulate the data by leveraging the reuse of a nonce in a session. Messages encrypted using a reused nonce value are susceptible to serious confidentiality and integrity attacks.

CVSS vector

CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:NExploitability: 1.2 | Impact: 5.2

Affected Packages6 packages

NVDlinuxfoundation/ceph< 14.2.21
Debianceph< 14.2.9-1+3
CVEListV5the_ceph_project/cephRed Hat Ceph Storage 4, Red Hat Openshift Container Storage 4.2+1

Also affects: Fedora 31

Patches

🔴Vulnerability Details

3
GHSA
GHSA-hcpq-vw4g-3vmh: A vulnerability was found in Red Hat Ceph Storage 4 and Red Hat Openshift Container Storage 42022-05-24
OSV
CVE-2020-1759: A vulnerability was found in Red Hat Ceph Storage 4 and Red Hat Openshift Container Storage 42020-04-13
CVEList
CVE-2020-1759: A vulnerability was found in Red Hat Ceph Storage 4 and Red Hat Openshift Container Storage 42020-04-13

📋Vendor Advisories

2
Red Hat
ceph: secure mode of msgr2 breaks both confidentiality and integrity aspects for long-lived sessions2020-04-06
Debian
CVE-2020-1759: ceph - A vulnerability was found in Red Hat Ceph Storage 4 and Red Hat Openshift Contai...2020

💬Community

2
Bugzilla
CVE-2020-1759 ceph: secure mode of msgr2 breaks both confidentiality and integrity aspects for long-lived sessions [fedora-all]2020-04-07
Bugzilla
CVE-2020-1759 ceph: secure mode of msgr2 breaks both confidentiality and integrity aspects for long-lived sessions2020-03-09
CVE-2020-1759 (MEDIUM CVSS 6.8) | A vulnerability was found in Red Ha | cvebase.io