Search CVE reports


Toggle filters

21 – 30 of 45 results


CVE-2020-10736

Medium priority

Some fixes available 2 of 3

An authorization bypass vulnerability was found in Ceph versions 15.2.0 before 15.2.2, where the ceph-mon and ceph-mgr daemons do not properly restrict access, resulting in gaining access to unauthorized resources. This flaw...

1 affected package

ceph

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ceph Fixed Not affected
Show less packages

CVE-2020-1760

Medium priority

Some fixes available 2 of 4

A flaw was found in the Ceph Object Gateway, where it supports request sent by an anonymous user in Amazon S3. This flaw could lead to potential XSS attacks due to the lack of proper neutralization of untrusted input.

1 affected package

ceph

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ceph Not affected Not affected Not affected Fixed
Show less packages

CVE-2020-12059

Medium priority
Fixed

An issue was discovered in Ceph through 13.2.9. A POST request with an invalid tagging XML can crash the RGW process by triggering a NULL pointer exception.

1 affected package

ceph

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ceph Not affected Fixed
Show less packages

CVE-2020-1699

Medium priority
Ignored

A path traversal flaw was found in the Ceph dashboard implemented in upstream versions v14.2.5, v14.2.6, v15.0.0 of Ceph storage and has been fixed in versions 14.2.7 and 15.1.0. An unauthenticated attacker could use this flaw to...

1 affected package

ceph

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ceph Not affected
Show less packages

CVE-2020-1759

Medium priority
Ignored

A vulnerability was found in Red Hat Ceph Storage 4 and Red Hat Openshift Container Storage 4.2 where, A nonce reuse vulnerability was discovered in the secure mode of the messenger v2 protocol, which can allow an attacker to...

1 affected package

ceph

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ceph Not affected Not affected
Show less packages

CVE-2020-1700

Medium priority

Some fixes available 2 of 3

A flaw was found in the way the Ceph RGW Beast front-end handles unexpected disconnects. An authenticated attacker can abuse this flaw by making multiple disconnect attempts resulting in a permanent leak of a socket connection by...

1 affected package

ceph

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ceph Fixed
Show less packages

CVE-2019-19337

Medium priority
Not affected

A flaw was found in Red Hat Ceph Storage version 3 in the way the Ceph RADOS Gateway daemon handles S3 requests. An authenticated attacker can abuse this flaw by causing a remote denial of service by sending a specially crafted...

1 affected package

ceph

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ceph Not affected
Show less packages

CVE-2019-10222

Medium priority
Fixed

A flaw was found in the Ceph RGW configuration with Beast as the front end handling client requests. An unauthenticated attacker could crash the Ceph RGW server by sending valid HTTP headers and terminating the...

1 affected package

ceph

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ceph Fixed
Show less packages

CVE-2019-3821

Medium priority
Fixed

A flaw was found in the way civetweb frontend was handling requests for ceph RGW server with SSL enabled. An unauthenticated attacker could create multiple connections to ceph RADOS gateway to exhaust file descriptors...

1 affected package

ceph

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ceph Not affected
Show less packages

CVE-2018-16889

Low priority
Fixed

Ceph does not properly sanitize encryption keys in debug logging for v4 auth. This results in the leaking of encryption key information in log files via plaintext. Versions up to v13.2.4 are vulnerable.

1 affected package

ceph

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ceph Fixed
Show less packages