CVE-2024-48916
- EPSS 0.02%
- Veröffentlicht 30.07.2025 19:45:00
- Zuletzt bearbeitet 31.07.2025 18:42:37
Ceph is a distributed object, block, and file storage platform. In versions 19.2.3 and below, it is possible to send an JWT that has "none" as JWT alg. And by doing so the JWT signature is not checked. The vulnerability is most likely in the RadosGW ...
CVE-2025-52555
- EPSS 0.04%
- Veröffentlicht 26.06.2025 20:21:05
- Zuletzt bearbeitet 30.06.2025 18:38:48
Ceph is a distributed object, block, and file storage platform. In versions 17.2.7, 18.2.1 through 18.2.4, and 19.0.0 through 19.2.2, an unprivileged user can escalate to root privileges in a ceph-fuse mounted CephFS by chmod 777 a directory owned by...
CVE-2020-1700
- EPSS 0.52%
- Veröffentlicht 07.02.2020 21:15:10
- Zuletzt bearbeitet 21.11.2024 05:11:11
A flaw was found in the way the Ceph RGW Beast front-end handles unexpected disconnects. An authenticated attacker can abuse this flaw by making multiple disconnect attempts resulting in a permanent leak of a socket connection by radosgw. This flaw c...
CVE-2019-10222
- EPSS 4.19%
- Veröffentlicht 08.11.2019 15:15:11
- Zuletzt bearbeitet 21.11.2024 04:18:41
A flaw was found in the Ceph RGW configuration with Beast as the front end handling client requests. An unauthenticated attacker could crash the Ceph RGW server by sending valid HTTP headers and terminating the connection, resulting in a remote denia...
CVE-2017-7519
- EPSS 0.07%
- Veröffentlicht 27.07.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:32:03
In Ceph, a format string flaw was found in the way libradosstriper parses input from user. A user could crash an application or service using the libradosstriper library.
CVE-2018-10861
- EPSS 0.58%
- Veröffentlicht 10.07.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:09
A flaw was found in the way ceph mon handles user requests. Any authenticated ceph user having read access to ceph can delete, create ceph storage pools and corrupt snapshot images. Ceph branches master, mimic, luminous and jewel are believed to be a...
CVE-2018-1129
- EPSS 0.39%
- Veröffentlicht 10.07.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:59:15
A flaw was found in the way signature calculation was handled by cephx authentication protocol. An attacker having access to ceph cluster network who is able to alter the message payload was able to bypass signature checks done by cephx protocol. Cep...
CVE-2017-12155
- EPSS 0.05%
- Veröffentlicht 12.12.2017 20:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
A resource-permission flaw was found in the openstack-tripleo-heat-templates package where ceph.client.openstack.keyring is created as world-readable. A local attacker with access to the key could read or modify data on Ceph cluster pools for OpenSta...