9.1
CVE-2022-0670
- EPSS 0.17%
- Veröffentlicht 25.07.2022 14:15:10
- Zuletzt bearbeitet 21.11.2024 06:39:09
- Quelle secalert@redhat.com
- Teams Watchlist Login
- Unerledigt Login
A flaw was found in Openstack manilla owning a Ceph File system "share", which enables the owner to read/write any manilla share or entire file system. The vulnerability is due to a bug in the "volumes" plugin in Ceph Manager. This allows an attacker to compromise Confidentiality and Integrity of a file system. Fixed in RHCS 5.2 and Ceph 17.2.2.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linuxfoundation ≫ Ceph Version >= 15.0.0 < 15.2.17
Linuxfoundation ≫ Ceph Version >= 16.0.0 < 16.2.10
Linuxfoundation ≫ Ceph Version >= 17.0.0 < 17.2.2
Redhat ≫ Ceph Storage Version < 5.2
Fedoraproject ≫ Fedora Version35
Fedoraproject ≫ Fedora Version36
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.17% | 0.391 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 9.1 | 3.9 | 5.2 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
|
CWE-863 Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.