Ceph

Ceph

13 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.18%
  • Veröffentlicht 27.08.2026 20:59:24
  • Zuletzt bearbeitet 08.09.2026 21:11:56

Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2.4 and 19.2.6, the Ceph Object Gateway (RGW) SigV4 handler does not reject requests that carry x-amz-* headers absent from the sig...

  • EPSS 0.16%
  • Veröffentlicht 27.08.2026 20:53:42
  • Zuletzt bearbeitet 08.09.2026 21:11:56

Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2.4 and 19.2.6, the Monitor subscription handler fails to properly authorize access to the configuration-key store, allowing any Ce...

  • EPSS 0.17%
  • Veröffentlicht 27.08.2026 20:47:01
  • Zuletzt bearbeitet 08.09.2026 21:11:56

Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2.4 and 19.2.6, the RADOS Gateway (RGW) protects STS session tokens with an AES-128-CBC handler that provides no message authentica...

  • EPSS 0.09%
  • Veröffentlicht 27.08.2026 20:34:41
  • Zuletzt bearbeitet 08.09.2026 21:11:56

Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2.4 and 19.2.6, the CephX authentication protocol encrypts tickets with AES-128-CBC in an unauthenticated mode that uses a hard-cod...

Exploit
  • EPSS 0.45%
  • Veröffentlicht 12.11.2025 18:28:18
  • Zuletzt bearbeitet 31.12.2025 16:23:56

Ceph is a distributed object, block, and file storage platform. In versions up to and including 19.2.3, using the argument `x-amz-copy-source` to put an object and specifying an empty string as its content leads to the RGW daemon crashing, resulting ...

  • EPSS 0.2%
  • Veröffentlicht 30.07.2025 19:45:00
  • Zuletzt bearbeitet 15.04.2026 00:35:42

Ceph is a distributed object, block, and file storage platform. In versions 19.2.3 and below, it is possible to send an JWT that has "none" as JWT alg. And by doing so the JWT signature is not checked. The vulnerability is most likely in the RadosGW ...

  • EPSS 0.18%
  • Veröffentlicht 26.06.2025 20:21:05
  • Zuletzt bearbeitet 15.04.2026 00:35:42

Ceph is a distributed object, block, and file storage platform. In versions 17.2.7, 18.2.1 through 18.2.4, and 19.0.0 through 19.2.2, an unprivileged user can escalate to root privileges in a ceph-fuse mounted CephFS by chmod 777 a directory owned by...

  • EPSS 2.49%
  • Veröffentlicht 07.02.2020 21:15:10
  • Zuletzt bearbeitet 21.11.2024 05:11:11

A flaw was found in the way the Ceph RGW Beast front-end handles unexpected disconnects. An authenticated attacker can abuse this flaw by making multiple disconnect attempts resulting in a permanent leak of a socket connection by radosgw. This flaw c...

  • EPSS 4.61%
  • Veröffentlicht 08.11.2019 15:15:11
  • Zuletzt bearbeitet 21.11.2024 04:18:41

A flaw was found in the Ceph RGW configuration with Beast as the front end handling client requests. An unauthenticated attacker could crash the Ceph RGW server by sending valid HTTP headers and terminating the connection, resulting in a remote denia...

Exploit
  • EPSS 0.5%
  • Veröffentlicht 27.07.2018 14:29:00
  • Zuletzt bearbeitet 21.11.2024 03:32:03

In Ceph, a format string flaw was found in the way libradosstriper parses input from user. A user could crash an application or service using the libradosstriper library.