cbcvebase.
CVE-2022-0670
published 2022-07-25

CVE-2022-0670: A flaw was found in Openstack manilla owning a Ceph File system "share", which enables the owner to read/write any manilla share or entire file system. The…

PriorityP351critical9.1CVSS 3.1
AVNACLPRNUINSUCHIHAN
EPSS
0.94%
56.9th percentile
A flaw was found in Openstack manilla owning a Ceph File system "share", which enables the owner to read/write any manilla share or entire file system. The vulnerability is due to a bug in the "volumes" plugin in Ceph Manager. This allows an attacker to compromise Confidentiality and Integrity of a file system. Fixed in RHCS 5.2 and Ceph 17.2.2.

Affected

25 ranges
VendorProductVersion rangeFixed in
debianceph< ceph 16.2.10+ds-1 (bookworm)ceph 16.2.10+ds-1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
linuxfoundationceph
linuxfoundationceph>= 0 < 14.2.21-1+deb11u214.2.21-1+deb11u2
linuxfoundationceph>= 0 < 16.2.10+ds-116.2.10+ds-1
linuxfoundationceph>= 0 < 16.2.10+ds-116.2.10+ds-1
linuxfoundationceph>= 0 < 16.2.10+ds-116.2.10+ds-1
linuxfoundationceph>= 15.0.0 < 15.2.1715.2.17
linuxfoundationceph>= 16.0.0 < 16.2.1016.2.10
linuxfoundationceph>= 17.0.0 < 17.2.217.2.2
msrcazl3_ceph_16.2.10-3_on_azure_linux_3.0
msrcazl3_ceph_18.2.1-1_on_azure_linux_3.0
msrcazure_linux_3.0_arm
msrcazure_linux_3.0_x64
msrccbl2_ceph_16.2.10-1_on_cbl_mariner_2.0
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64
msrccm1_ceph_16.2.10-1_on_cbl_mariner_1.0
redhatceph_storage< 5.25.2
redhatceph_storage>= 0 < 12.2.13-0ubuntu0.18.04.1112.2.13-0ubuntu0.18.04.11
redhatceph_storage>= 0 < 15.2.17-0ubuntu0.20.04.315.2.17-0ubuntu0.20.04.3
redhatceph_storage>= 0 < 17.2.5-0ubuntu0.22.04.317.2.5-0ubuntu0.22.04.3

CVSS provenance

nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
osv9.1CRITICAL
vendor_debian9.1CRITICAL
vendor_msrc9.1CRITICAL
vendor_redhat9.1CRITICAL
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.