Lucene search

K
mageiaGentoo FoundationMGASA-2023-0139
HistoryApr 15, 2023 - 10:03 p.m.

Updated ceph packages fix security vulnerability

2023-04-1522:03:44
Gentoo Foundation
advisories.mageia.org
20
ceph
openstack
manilla
security vulnerability
ceph file system
confidentiality
integrity
bug
privilege escalation
information disclosure
cve-2022-0670
cve-2022-3650

9.1 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

0.001 Low

EPSS

Percentile

49.8%

Openstack manilla owning a Ceph File system “share”, enables the owner to read/write any manilla share or entire file system. The vulnerability is due to a bug in the “volumes” plugin in Ceph Manager. This allows an attacker to compromise Confidentiality and Integrity of a file system. (CVE-2022-0670) Privilege escalation and privileged information disclosure (CVE-2022-3650)

OSVersionArchitecturePackageVersionFilename
Mageia8noarchceph< 15.2.17-1ceph-15.2.17-1.mga8

9.1 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

0.001 Low

EPSS

Percentile

49.8%