CVE-2020-27781
Summary
| CVE | CVE-2020-27781 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-12-18 21:15:00 UTC |
| Updated | 2023-11-07 03:21:00 UTC |
| Description | User credentials can be manipulated and stolen by Native CephFS consumers of OpenStack Manila, resulting in potential privilege escalation. An Open Stack Manila user can request access to a share to an arbitrary cephx user, including existing users. The access key is retrieved via the interface drivers. Then, all users of the requesting OpenStack project can view the access key. This enables the attacker to target any resource that the user has access to. This can be done to even "admin" users, compromising the ceph administrator. This flaw affects Ceph versions prior to 14.2.16, 15.x prior to 15.2.8, and 16.x prior to 16.2.0. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] [DLA 3629-1] ceph security update |
MLIST |
lists.debian.org |
|
| [SECURITY] Fedora 33 Update: ceph-15.2.8-1.fc33 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 33 Update: ceph-15.2.8-1.fc33 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| Ceph: Multiple vulnerabilities (GLSA 202105-39) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| 1900109 – (CVE-2020-27781) CVE-2020-27781 Ceph: User credentials can be manipulated and stolen by Native CephFS consumers of OpenStack Manila |
MISC |
bugzilla.redhat.com |
Issue Tracking, Vendor Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 198423 Ubuntu Security Notification for Ceph vulnerabilities (USN-4998-1)
- 198554 Ubuntu Security Notification for Ceph Vulnerabilities (USN-5128-1)
- 239757 Red Hat Update for red hat ceph storage 4.2 (RHSA-2021:0081)
- 500843 Alpine Linux Security Update for ceph
- 501532 Alpine Linux Security Update for ceph
- 502826 Alpine Linux Security Update for ceph16
- 6000278 Debian Security Update for ceph (DLA 3629-1)
- 710075 Gentoo Linux Ceph Multiple vulnerabilities (GLSA 202105-39)
- 750422 OpenSUSE Security Update for ceph (openSUSE-SU-2021:0079-1)
- 750466 OpenSUSE Security Update for ceph (openSUSE-SU-2020:2327-1)