CVE-2024-48916
- EPSS 0.02%
- Published 30.07.2025 19:45:00
- Last modified 31.07.2025 18:42:37
Ceph is a distributed object, block, and file storage platform. In versions 19.2.3 and below, it is possible to send an JWT that has "none" as JWT alg. And by doing so the JWT signature is not checked. The vulnerability is most likely in the RadosGW ...
CVE-2025-52555
- EPSS 0.04%
- Published 26.06.2025 20:21:05
- Last modified 30.06.2025 18:38:48
Ceph is a distributed object, block, and file storage platform. In versions 17.2.7, 18.2.1 through 18.2.4, and 19.0.0 through 19.2.2, an unprivileged user can escalate to root privileges in a ceph-fuse mounted CephFS by chmod 777 a directory owned by...
CVE-2020-1700
- EPSS 0.52%
- Published 07.02.2020 21:15:10
- Last modified 21.11.2024 05:11:11
A flaw was found in the way the Ceph RGW Beast front-end handles unexpected disconnects. An authenticated attacker can abuse this flaw by making multiple disconnect attempts resulting in a permanent leak of a socket connection by radosgw. This flaw c...
CVE-2019-10222
- EPSS 4.19%
- Published 08.11.2019 15:15:11
- Last modified 21.11.2024 04:18:41
A flaw was found in the Ceph RGW configuration with Beast as the front end handling client requests. An unauthenticated attacker could crash the Ceph RGW server by sending valid HTTP headers and terminating the connection, resulting in a remote denia...
CVE-2017-7519
- EPSS 0.07%
- Published 27.07.2018 14:29:00
- Last modified 21.11.2024 03:32:03
In Ceph, a format string flaw was found in the way libradosstriper parses input from user. A user could crash an application or service using the libradosstriper library.
CVE-2018-10861
- EPSS 0.58%
- Published 10.07.2018 14:29:00
- Last modified 21.11.2024 03:42:09
A flaw was found in the way ceph mon handles user requests. Any authenticated ceph user having read access to ceph can delete, create ceph storage pools and corrupt snapshot images. Ceph branches master, mimic, luminous and jewel are believed to be a...
CVE-2018-1129
- EPSS 0.39%
- Published 10.07.2018 14:29:00
- Last modified 21.11.2024 03:59:15
A flaw was found in the way signature calculation was handled by cephx authentication protocol. An attacker having access to ceph cluster network who is able to alter the message payload was able to bypass signature checks done by cephx protocol. Cep...
CVE-2017-12155
- EPSS 0.05%
- Published 12.12.2017 20:29:00
- Last modified 20.04.2025 01:37:25
A resource-permission flaw was found in the openstack-tripleo-heat-templates package where ceph.client.openstack.keyring is created as world-readable. A local attacker with access to the key could read or modify data on Ceph cluster pools for OpenSta...