Lucene search

K
ubuntucveUbuntu.comUB:CVE-2020-27781
HistoryDec 18, 2020 - 12:00 a.m.

CVE-2020-27781

2020-12-1800:00:00
ubuntu.com
ubuntu.com
17

3.6 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:P/A:N

7.1 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

0.0004 Low

EPSS

Percentile

15.8%

User credentials can be manipulated and stolen by Native CephFS consumers
of OpenStack Manila, resulting in potential privilege escalation. An Open
Stack Manila user can request access to a share to an arbitrary cephx user,
including existing users. The access key is retrieved via the interface
drivers. Then, all users of the requesting OpenStack project can view the
access key. This enables the attacker to target any resource that the user
has access to. This can be done to even “admin” users, compromising the
ceph administrator. This flaw affects Ceph versions prior to 14.2.16, 15.x
prior to 15.2.8, and 16.x prior to 16.2.0.

Bugs

OSVersionArchitecturePackageVersionFilename
ubuntu18.04noarchceph< 12.2.13-0ubuntu0.18.04.10UNKNOWN
ubuntu20.04noarchceph< 15.2.12-0ubuntu0.20.04.1UNKNOWN
ubuntu20.10noarchceph< 15.2.12-0ubuntu0.20.10.1UNKNOWN
ubuntu21.04noarchceph< 16.2.0-0ubuntu1UNKNOWN
ubuntu21.10noarchceph< 16.2.0-0ubuntu1UNKNOWN
ubuntu22.04noarchceph< 16.2.0-0ubuntu1UNKNOWN
ubuntu22.10noarchceph< 16.2.0-0ubuntu1UNKNOWN
ubuntu23.04noarchceph< 16.2.0-0ubuntu1UNKNOWN
ubuntu23.10noarchceph< 16.2.0-0ubuntu1UNKNOWN
ubuntu24.04noarchceph< 16.2.0-0ubuntu1UNKNOWN
Rows per page:
1-10 of 121

3.6 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:P/A:N

7.1 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

0.0004 Low

EPSS

Percentile

15.8%