Lucene search

K
nvd[email protected]NVD:CVE-2018-10861
HistoryJul 10, 2018 - 2:29 p.m.

CVE-2018-10861

2018-07-1014:29:00
CWE-287
CWE-285
web.nvd.nist.gov
1

5.5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:N/I:P/A:P

8.1 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

6.8 Medium

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

75.1%

A flaw was found in the way ceph mon handles user requests. Any authenticated ceph user having read access to ceph can delete, create ceph storage pools and corrupt snapshot images. Ceph branches master, mimic, luminous and jewel are believed to be affected.

Affected configurations

NVD
Node
cephcephMatch10.2.0
OR
cephcephMatch10.2.1
OR
cephcephMatch10.2.2
OR
cephcephMatch10.2.3
OR
cephcephMatch10.2.4
OR
cephcephMatch10.2.5
OR
cephcephMatch10.2.6
OR
cephcephMatch10.2.7
OR
cephcephMatch10.2.8
OR
cephcephMatch10.2.9
OR
cephcephMatch10.2.10
OR
cephcephMatch10.2.11
OR
cephcephMatch12.2.0
OR
cephcephMatch12.2.1
OR
cephcephMatch12.2.2
OR
cephcephMatch12.2.3
OR
cephcephMatch12.2.4
OR
cephcephMatch12.2.5
OR
cephcephMatch12.2.6
OR
cephcephMatch12.2.7
OR
cephcephMatch13.2.0
OR
cephcephMatch13.2.1
Node
redhatceph_storageMatch3
OR
redhatceph_storage_monMatch2
OR
redhatceph_storage_monMatch3
OR
redhatceph_storage_osdMatch2
OR
redhatceph_storage_osdMatch3
OR
redhatenterprise_linux_desktopMatch7.0
OR
redhatenterprise_linux_serverMatch7.0
OR
redhatenterprise_linux_workstationMatch7.0
Node
opensuseleapMatch15.0
Node
debiandebian_linuxMatch9.0

5.5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:N/I:P/A:P

8.1 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

6.8 Medium

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

75.1%