CVE-2024-31884
published 2026-01-20CVE-2024-31884: pybind: Improper use of Pybind A flaw was found in Ceph. An attacker can allow Ceph to accept any certificate because no certificate context is passed via…
high7.5
pybind: Improper use of Pybind
A flaw was found in Ceph. An attacker can allow Ceph to accept any certificate because no certificate context is passed via Pybind to the constructors imaplib.IMAP4_SSL or smtplib.SMTP_SSL. As a result, pybind pybind does not check the server's X.509
certificate, instead accepting any certificate. This enables an attacker to commit a Man In the Middle (MITM) attack, compromising mail server credentials or mail contents
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ceph | < ceph 14.2.21-1+deb11u3 (bullseye) | ceph 14.2.21-1+deb11u3 (bullseye) |
CVSS provenance
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
ceph vulnerabilities
osv·2026-02-24·CVSS 7.5
CVE-2024-31884 [HIGH] ceph vulnerabilities
ceph vulnerabilities
Martin Schobert discovered that Ceph did not properly verify SSL
certificates when using Pybind for secure mail connections, which could
result in accepting invalid certificates. An attacker could possibly use
this issue to perform an intermediary attack and access mail server
credentials or message contents. This issue only affected Ubuntu 20.04 LTS,
Ubuntu 22.04 LTS, Ubuntu 24.04 LTS and Ubuntu 25.10. (CVE-2024-31884)
It was discovered that Ceph's RADOS Gateway (RGW) did not properly handle
certain header parameters. An attacker could possibly use this issue to
cause the RGW service to crash, leading to a denial of service.
(CVE-2024-47866)
OSV
CVE-2024-31884: Incorrect usage of certificate checking via Pybind
osv·2026-01-21
CVE-2024-31884 CVE-2024-31884: Incorrect usage of certificate checking via Pybind
Incorrect usage of certificate checking via Pybind
Ubuntu
Ceph vulnerabilities
vendor_ubuntu·2026-02-24·CVSS 7.5
CVE-2024-47866 [HIGH] Ceph vulnerabilities
Title: Ceph vulnerabilities
Summary: Several security issues were fixed in Ceph.
Martin Schobert discovered that Ceph did not properly verify SSL
certificates when using Pybind for secure mail connections, which could
result in accepting invalid certificates. An attacker could possibly use
this issue to perform an intermediary attack and access mail server
credentials or message contents. This issue only affected Ubuntu 20.04 LTS,
Ubuntu 22.04 LTS, Ubuntu 24.04 LTS and Ubuntu 25.10. (CVE-2024-31884)
It was discovered that Ceph's RADOS Gateway (RGW) did not properly handle
certain header parameters. An attacker could possibly use this issue to
cause the RGW service to crash, leading to a denial of service.
(CVE-2024-47866)
Instructions: In general, a standard system update will make all
Red Hat
pybind: Improper use of Pybind
vendor_redhat·2026-01-20·CVSS 6.5
CVE-2024-31884 [MEDIUM] CWE-295 pybind: Improper use of Pybind
pybind: Improper use of Pybind
A flaw was found in Ceph. An attacker can allow Ceph to accept any certificate because no certificate context is passed via Pybind to the constructors imaplib.IMAP4_SSL or smtplib.SMTP_SSL. As a result, pybind pybind does not check the server's X.509
certificate, instead accepting any certificate. This enables an attacker to commit a Man In the Middle (MITM) attack, compromising mail server credentials or mail contents
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Debian
CVE-2024-31884: ceph
vendor_debian·2024
CVE-2024-31884 CVE-2024-31884: ceph
bookworm: open
bullseye: resolved (fixed in 14.2.21-1+deb11u3)
forky: resolved (fixed in 18.2.8+ds-1)
sid: resolved (fixed in 18.2.8+ds-1)
trixie: open
No detection rules found.
No public exploits indexed.
2026-01-20
Published