6.5
CVE-2018-1129
- EPSS 1.9%
- Veröffentlicht 10.07.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:59:15
- Erkennungen
A flaw was found in the way signature calculation was handled by cephx authentication protocol. An attacker having access to ceph cluster network who is able to alter the message payload was able to bypass signature checks done by cephx protocol. Ceph branches master, mimic, luminous and jewel are believed to be vulnerable.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Redhat ≫ Ceph Storage Version 1.3
Redhat ≫ Ceph Storage Version 3
Redhat ≫ Ceph Storage Mon Version 2
Redhat ≫ Ceph Storage Mon Version 3
Redhat ≫ Ceph Storage Osd Version 2
Redhat ≫ Ceph Storage Osd Version 3
Redhat ≫ Enterprise Linux Version 7.0
Redhat ≫ Enterprise Linux Desktop Version 7.0
Redhat ≫ Enterprise Linux Server Version 7.0
Redhat ≫ Enterprise Linux Workstation Version 7.0
Debian ≫ Debian Linux Version 8.0
Debian ≫ Debian Linux Version 9.0
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.9% | 0.77 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 6.5 | 2.8 | 3.6 |
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
|
| NIST | 3.3 | 6.5 | 2.9 |
AV:A/AC:L/Au:N/C:N/I:P/A:N
|
CWE-284 Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
CWE-287 Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
https://lists.debian.org/debian-lts-announce/2019/03/msg00017.html
http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00100.html
https://access.redhat.com/errata/RHSA-2018:2177
https://access.redhat.com/errata/RHSA-2018:2179
https://access.redhat.com/errata/RHSA-2018:2261
https://access.redhat.com/errata/RHSA-2018:2274
https://www.debian.org/security/2018/dsa-4339
http://packetstormsecurity.com/files/154245/Kernel-Live-Patch-Security-Notice-LSN-0054-1.html
http://tracker.ceph.com/issues/24837
https://bugzilla.redhat.com/show_bug.cgi?id=1576057
https://github.com/ceph/ceph/commit/8f396cf35a3826044b089141667a196454c0a587