Known Vulnerabilities for Ceph by Redhat
Listed below are 10 of the newest known vulnerabilities associated with "Ceph" by "Redhat".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2022-3650 json | A privilege escalation flaw was found in Ceph. Ceph-crash.service allows a local attacker to escalate privileges to root in t... | 7.8 - HIGH | 2023-01-17 | 2023-12-23 |
| CVE-2021-3531 json | A flaw was found in the Red Hat Ceph Storage RGW in versions before 14.2.21. When processing a GET Request for a swift URL th... | 5.3 - MEDIUM | 2021-05-18 | 2023-11-07 |
| CVE-2021-3524 json | A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway) in versions before 14.2.21. The vulnerability is r... | 6.5 - MEDIUM | 2021-05-17 | 2023-11-07 |
| CVE-2020-27839 json | A flaw was found in ceph-dashboard. The JSON Web Token (JWT) used for user authentication is stored by the frontend applicati... | 5.4 - MEDIUM | 2021-05-26 | 2021-06-03 |
| CVE-2020-27781 json | User credentials can be manipulated and stolen by Native CephFS consumers of OpenStack Manila, resulting in potential privile... | 7.1 - HIGH | 2020-12-18 | 2023-11-07 |
| CVE-2020-25678 json | A flaw was found in ceph in versions prior to 16.y.z where ceph stores mgr module passwords in clear text. This can be found ... | 4.4 - MEDIUM | 2021-01-08 | 2023-10-23 |
| CVE-2020-25660 json | A flaw was found in the Cephx authentication protocol in versions before 15.2.6 and before 14.2.14, where it does not verify ... | 8.8 - HIGH | 2020-11-23 | 2023-11-07 |
| CVE-2018-16889 json | Ceph does not properly sanitize encryption keys in debug logging for v4 auth. This results in the leaking of encryption key i... | 7.5 - HIGH | 2019-01-28 | 2023-02-13 |
| CVE-2018-16846 json | It was found in Ceph versions before 13.2.4 that authenticated ceph RGW users can cause a denial of service against OMAPs hol... | 6.5 - MEDIUM | 2019-01-15 | 2022-04-19 |
| CVE-2018-14662 json | It was found Ceph versions before 13.2.4 that authenticated ceph users with read only permissions could steal dm-crypt encryp... | 5.7 - MEDIUM | 2019-01-15 | 2022-04-19 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Redhat | Ceph | 9.2.1 | |||
| Application | Redhat | Ceph | 9.2.0 | |||
| Application | Redhat | Ceph | 9.1.0 | |||
| Application | Redhat | Ceph | 9.0.3 | |||
| Application | Redhat | Ceph | 9.0.2 | |||
| Application | Redhat | Ceph | 9.0.1 | |||
| Application | Redhat | Ceph | 9.0.0 | |||
| Application | Redhat | Ceph | 16.2.0 | |||
| Application | Redhat | Ceph | 15.2.7 | |||
| Application | Redhat | Ceph | 15.2.6 | |||
| Application | Redhat | Ceph | 15.2.5 | |||
| Application | Redhat | Ceph | 15.2.4 | |||
| Application | Redhat | Ceph | 15.2.3 | |||
| Application | Redhat | Ceph | 15.2.2 | |||
| Application | Redhat | Ceph | 15.2.1 | |||
| Application | Redhat | Ceph | 15.2.0 | |||
| Application | Redhat | Ceph | 15.1.1 | |||
| Application | Redhat | Ceph | 15.1.0 | |||
| Application | Redhat | Ceph | 15.0.0 | |||
| Application | Redhat | Ceph | 14.2.15 |