CVE-2020-27781

Severity
7.1HIGH
EPSS
0.1%
top 78.26%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 18
Latest updateMay 24

Description

User credentials can be manipulated and stolen by Native CephFS consumers of OpenStack Manila, resulting in potential privilege escalation. An Open Stack Manila user can request access to a share to an arbitrary cephx user, including existing users. The access key is retrieved via the interface drivers. Then, all users of the requesting OpenStack project can view the access key. This enables the attacker to target any resource that the user has access to. This can be done to even "admin" users,

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:NExploitability: 1.8 | Impact: 5.2

Affected Packages6 packages

NVDredhat/ceph15.0.015.2.8+2
Debianceph< 14.2.16-1+3
Ubuntuceph< 12.2.13-0ubuntu0.18.04.10+1
CVEListV5cephCeph 16.2.0

Also affects: Fedora 33, Openshift Container Platform 4.0

🔴Vulnerability Details

5
GHSA
GHSA-mh9p-7vgq-83jw: User credentials can be manipulated and stolen by Native CephFS consumers of OpenStack Manila, resulting in potential privilege escalation2022-05-24
OSV
ceph vulnerabilities2021-11-01
OSV
ceph vulnerabilities2021-06-25
OSV
CVE-2020-27781: User credentials can be manipulated and stolen by Native CephFS consumers of OpenStack Manila, resulting in potential privilege escalation2020-12-18
CVEList
CVE-2020-27781: User credentials can be manipulated and stolen by Native CephFS consumers of OpenStack Manila, resulting in potential privilege escalation2020-12-18

📋Vendor Advisories

4
Ubuntu
Ceph vulnerabilities2021-11-01
Ubuntu
Ceph vulnerabilities2021-06-25
Red Hat
ceph: User credentials can be manipulated and stolen by Native CephFS consumers of OpenStack Manila2020-12-16
Debian
CVE-2020-27781: ceph - User credentials can be manipulated and stolen by Native CephFS consumers of Ope...2020
CVE-2020-27781 (HIGH CVSS 7.1) | User credentials can be manipulated | cvebase.io