Redhat Ceph Storage vulnerabilities
45 known vulnerabilities affecting redhat/ceph_storage.
Total CVEs
45
CISA KEV
1
actively exploited
Public exploits
3
Exploited in wild
2
Severity breakdown
CRITICAL7HIGH15MEDIUM23
Vulnerabilities
Page 3 of 3
CVE-2018-1059P4MEDIUMCVSS 6.1v3.02018-04-24
CVE-2018-1059 [MEDIUM] CWE-200 CVE-2018-1059: The DPDK vhost-user interface does not check to verify that all the requested guest physical range i
The DPDK vhost-user interface does not check to verify that all the requested guest physical range is mapped and contiguous when performing Guest Physical Addresses to Host Virtual Addresses translations. This may lead to a malicious guest exposing vhost-user backend process memory. All versions before 18.02.1 are vulnerable.
nvd
CVE-2018-14662P4MEDIUMCVSS 5.7v2.0v3.02019-01-15
CVE-2018-14662 [MEDIUM] CWE-285 CVE-2018-14662: It was found Ceph versions before 13.2.4 that authenticated ceph users with read only permissions co
It was found Ceph versions before 13.2.4 that authenticated ceph users with read only permissions could steal dm-crypt encryption keys used in ceph disk encryption.
nvd
CVE-2020-12458P4MEDIUMCVSS 5.5v3.0v4.02020-04-29
CVE-2020-12458 [MEDIUM] CWE-732 CVE-2020-12458: An information-disclosure flaw was found in Grafana through 6.7.3. The database directory /var/lib/g
An information-disclosure flaw was found in Grafana through 6.7.3. The database directory /var/lib/grafana and database file /var/lib/grafana/grafana.db are world readable. This can result in exposure of sensitive information (e.g., cleartext or encrypted datasource passwords).
nvd
CVE-2020-25677P4MEDIUMCVSS 5.5v3.0v4.02020-12-08
CVE-2020-25677 [MEDIUM] CWE-312 CVE-2020-25677: A flaw was found in Ceph-ansible v4.0.41 where it creates an /etc/ceph/iscsi-gateway.conf with insec
A flaw was found in Ceph-ansible v4.0.41 where it creates an /etc/ceph/iscsi-gateway.conf with insecure default permissions. This flaw allows any user on the system to read sensitive information within this file. The highest threat from this vulnerability is to confidentiality.
nvd
CVE-2020-25678P4MEDIUMCVSS 4.4v4.02021-01-08
CVE-2020-25678 [MEDIUM] CWE-312 CVE-2020-25678: A flaw was found in ceph in versions prior to 16.y.z where ceph stores mgr module passwords in clear
A flaw was found in ceph in versions prior to 16.y.z where ceph stores mgr module passwords in clear text. This can be found by searching the mgr logs for grafana and dashboard, with passwords visible.
nvd
← Previous3 / 3