cbcvebase.

Debian Ceph vulnerabilities

36 known vulnerabilities affecting debian/ceph.

Total CVEs
36
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH12MEDIUM20LOW2UNKNOWN1

Vulnerabilities

Page 2 of 2
CVE-2021-3524P4MEDIUMCVSS 5.4fixed in ceph 14.2.21-1 (bookworm)2021
CVE-2021-3524 [MEDIUM] CVE-2021-3524: ceph - A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway) in ve... A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway) in versions before 14.2.21. The vulnerability is related to the injection of HTTP headers via a CORS ExposeHeader tag. The newline character in the ExposeHeader tag in the CORS configuration file generates a header injection in the response when the CORS request is made. In addition, the prior b
debian
CVE-2016-8626P4MEDIUMCVSS 6.5fixed in ceph 10.2.5-1 (bookworm)2016
CVE-2016-8626 [MEDIUM] CVE-2016-8626: ceph - A flaw was found in Red Hat Ceph before 0.94.9-8. The way Ceph Object Gateway ha... A flaw was found in Red Hat Ceph before 0.94.9-8. The way Ceph Object Gateway handles POST object requests permits an authenticated attacker to launch a denial of service attack by sending null or specially crafted POST object requests. Scope: local bookworm: resolved (fixed in 10.2.5-1) bullseye: resolved (fixed in 10.2.5-1) forky: resolved (fixed in 10.2.5-1) sid: re
debian
CVE-2018-1129P4MEDIUMCVSS 6.5fixed in ceph 12.2.8+dfsg1-1 (bookworm)2018
CVE-2018-1129 [MEDIUM] CVE-2018-1129: ceph - A flaw was found in the way signature calculation was handled by cephx authentic... A flaw was found in the way signature calculation was handled by cephx authentication protocol. An attacker having access to ceph cluster network who is able to alter the message payload was able to bypass signature checks done by cephx protocol. Ceph branches master, mimic, luminous and jewel are believed to be vulnerable. Scope: local bookworm: resolved (fixed in 12.
debian
CVE-2020-1759P4MEDIUMCVSS 6.4fixed in ceph 14.2.9-1 (bookworm)2020
CVE-2020-1759 [MEDIUM] CVE-2020-1759: ceph - A vulnerability was found in Red Hat Ceph Storage 4 and Red Hat Openshift Contai... A vulnerability was found in Red Hat Ceph Storage 4 and Red Hat Openshift Container Storage 4.2 where, A nonce reuse vulnerability was discovered in the secure mode of the messenger v2 protocol, which can allow an attacker to forge auth tags and potentially manipulate the data by leveraging the reuse of a nonce in a session. Messages encrypted using a reused nonce valu
debian
CVE-2020-27839P4MEDIUMCVSS 5.4fixed in ceph 14.2.18-1 (bookworm)2020
CVE-2020-27839 [MEDIUM] CVE-2020-27839: ceph - A flaw was found in ceph-dashboard. The JSON Web Token (JWT) used for user authe... A flaw was found in ceph-dashboard. The JSON Web Token (JWT) used for user authentication is stored by the frontend application in the browser’s localStorage which is potentially vulnerable to attackers via XSS attacks. The highest threat from this vulnerability is to data confidentiality and integrity. Scope: local bookworm: resolved (fixed in 14.2.18-1) bullseye: r
debian
CVE-2018-16846P4MEDIUMCVSS 6.5fixed in ceph 12.2.11+dfsg1-1 (bookworm)2018
CVE-2018-16846 [MEDIUM] CVE-2018-16846: ceph - It was found in Ceph versions before 13.2.4 that authenticated ceph RGW users ca... It was found in Ceph versions before 13.2.4 that authenticated ceph RGW users can cause a denial of service against OMAPs holding bucket indices. Scope: local bookworm: resolved (fixed in 12.2.11+dfsg1-1) bullseye: resolved (fixed in 12.2.11+dfsg1-1) forky: resolved (fixed in 12.2.11+dfsg1-1) sid: resolved (fixed in 12.2.11+dfsg1-1) trixie: resolved (fixed in 12.2.11
debian
CVE-2022-3854P4MEDIUMCVSS 6.5fixed in ceph 16.2.10+ds-5 (bookworm)2022
CVE-2022-3854 [MEDIUM] CVE-2022-3854: ceph - A flaw was found in Ceph, relating to the URL processing on RGW backends. An att... A flaw was found in Ceph, relating to the URL processing on RGW backends. An attacker can exploit the URL processing by providing a null URL to crash the RGW, causing a denial of service. Scope: local bookworm: resolved (fixed in 16.2.10+ds-5) bullseye: resolved forky: resolved (fixed in 16.2.10+ds-5) sid: resolved (fixed in 16.2.10+ds-5) trixie: resolved (fixed in 16.
debian
CVE-2021-3531P4MEDIUMCVSS 5.3fixed in ceph 14.2.21-1 (bookworm)2021
CVE-2021-3531 [MEDIUM] CVE-2021-3531: ceph - A flaw was found in the Red Hat Ceph Storage RGW in versions before 14.2.21. Whe... A flaw was found in the Red Hat Ceph Storage RGW in versions before 14.2.21. When processing a GET Request for a swift URL that ends with two slashes it can cause the rgw to crash, resulting in a denial of service. The greatest threat to the system is of availability. Scope: local bookworm: resolved (fixed in 14.2.21-1) bullseye: resolved (fixed in 14.2.21-1) forky: re
debian
CVE-2021-3509P4MEDIUMCVSS 5.4fixed in ceph 14.2.21-1 (bookworm)2021
CVE-2021-3509 [MEDIUM] CVE-2021-3509: ceph - A flaw was found in Red Hat Ceph Storage 4, in the Dashboard component. In respo... A flaw was found in Red Hat Ceph Storage 4, in the Dashboard component. In response to CVE-2020-27839, the JWT token was moved from localStorage to an httpOnly cookie. However, token cookies are used in the body of the HTTP response for the documentation, which again makes it available to XSS.The greatest threat to the system is for confidentiality, integrity, and avai
debian
CVE-2020-1760P4MEDIUMCVSS 5.8fixed in ceph 14.2.9-1 (bookworm)2020
CVE-2020-1760 [MEDIUM] CVE-2020-1760: ceph - A flaw was found in the Ceph Object Gateway, where it supports request sent by a... A flaw was found in the Ceph Object Gateway, where it supports request sent by an anonymous user in Amazon S3. This flaw could lead to potential XSS attacks due to the lack of proper neutralization of untrusted input. Scope: local bookworm: resolved (fixed in 14.2.9-1) bullseye: resolved (fixed in 14.2.9-1) forky: resolved (fixed in 14.2.9-1) sid: resolved (fixed in 14
debian
CVE-2016-5009P4MEDIUMCVSS 6.5fixed in ceph 10.2.5-1 (bookworm)2016
CVE-2016-5009 [MEDIUM] CVE-2016-5009: ceph - The handle_command function in mon/Monitor.cc in Ceph allows remote authenticate... The handle_command function in mon/Monitor.cc in Ceph allows remote authenticated users to cause a denial of service (segmentation fault and ceph monitor crash) via an (1) empty or (2) crafted prefix. Scope: local bookworm: resolved (fixed in 10.2.5-1) bullseye: resolved (fixed in 10.2.5-1) forky: resolved (fixed in 10.2.5-1) sid: resolved (fixed in 10.2.5-1) trixie: r
debian
CVE-2015-5245P4MEDIUMCVSS 4.3fixed in ceph 0.80.10-1 (bookworm)2015
CVE-2015-5245 [MEDIUM] CVE-2015-5245: ceph - CRLF injection vulnerability in the Ceph Object Gateway (aka radosgw or RGW) in ... CRLF injection vulnerability in the Ceph Object Gateway (aka radosgw or RGW) in Ceph before 0.94.4 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted bucket name. Scope: local bookworm: resolved (fixed in 0.80.10-1) bullseye: resolved (fixed in 0.80.10-1) forky: resolved (fixed in 0.80.10-1) sid: resolved
debian
CVE-2018-14662P4MEDIUMCVSS 5.7fixed in ceph 12.2.11+dfsg1-1 (bookworm)2018
CVE-2018-14662 [MEDIUM] CVE-2018-14662: ceph - It was found Ceph versions before 13.2.4 that authenticated ceph users with read... It was found Ceph versions before 13.2.4 that authenticated ceph users with read only permissions could steal dm-crypt encryption keys used in ceph disk encryption. Scope: local bookworm: resolved (fixed in 12.2.11+dfsg1-1) bullseye: resolved (fixed in 12.2.11+dfsg1-1) forky: resolved (fixed in 12.2.11+dfsg1-1) sid: resolved (fixed in 12.2.11+dfsg1-1) trixie: resolve
debian
CVE-2020-25678P4MEDIUMCVSS 4.4fixed in ceph 14.2.18-1 (bookworm)2020
CVE-2020-25678 [MEDIUM] CVE-2020-25678: ceph - A flaw was found in ceph in versions prior to 16.y.z where ceph stores mgr modul... A flaw was found in ceph in versions prior to 16.y.z where ceph stores mgr module passwords in clear text. This can be found by searching the mgr logs for grafana and dashboard, with passwords visible. Scope: local bookworm: resolved (fixed in 14.2.18-1) bullseye: resolved (fixed in 14.2.18-1) forky: resolved (fixed in 14.2.18-1) sid: resolved (fixed in 14.2.18-1) tr
debian
CVE-2017-7519P4LOWCVSS 2.3fixed in ceph 12.2.8+dfsg1-1 (bookworm)2017
CVE-2017-7519 [LOW] CVE-2017-7519: ceph - In Ceph, a format string flaw was found in the way libradosstriper parses input ... In Ceph, a format string flaw was found in the way libradosstriper parses input from user. A user could crash an application or service using the libradosstriper library. Scope: local bookworm: resolved (fixed in 12.2.8+dfsg1-1) bullseye: resolved (fixed in 12.2.8+dfsg1-1) forky: resolved (fixed in 12.2.8+dfsg1-1) sid: resolved (fixed in 12.2.8+dfsg1-1) trixie: resolved (
debian
CVE-2024-31884UNKNOWNfixed in ceph 14.2.21-1+deb11u3 (bullseye)2024
CVE-2024-31884 CVE-2024-31884: ceph bookworm: open bullseye: resolved (fixed in 14.2.21-1+deb11u3) forky: resolved (fixed in 18.2.8+ds-1) sid: resolved (fixed in 18.2.8+ds-1) trixie: open
debian
Debian Ceph vulnerabilities | cvebase