CVEs (8)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Fedoraproject LinuxfoundationRedhat3Ceph Ceph StorageFedoraJun 17, 2026 Jul 25, 2022 N/A· v4 9.1 CRITICAL· v3 N/A· v2 A flaw was found in Openstack manilla owning a Ceph File system "share", which enables the owner to read/write any manilla share or entire file system. The vulnerability is due to a bug in the "volumes" plugin in Ceph Ma...Show more |
4Debian FedoraprojectLinuxfoundation+1 more4Ceph Ceph StorageDebian Linux+1 moreJun 17, 2026 Apr 15, 2021 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 An authentication flaw was found in ceph in versions before 14.2.20. When the monitor handles CEPHX_GET_AUTH_SESSION_KEY requests, it doesn't sanitize other_keys, allowing key reuse. An attacker who can request a global_...Show more |
5Canonical FedoraprojectLinuxfoundation+2 more6Ceph Ceph StorageFedora+3 moreJun 17, 2026 Jun 26, 2020 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway). The vulnerability is related to the injection of HTTP headers via a CORS ExposeHeader tag. The newline character in the ExposeHeader tag in the...Show more |
An authorization bypass vulnerability was found in Ceph versions 15.2.0 before 15.2.2, where the ceph-mon and ceph-mgr daemons do not properly restrict access, resulting in gaining access to unauthorized resources. This...Show more |
5Canonical DebianFedoraproject+2 more6Ceph Ceph StorageDebian Linux+3 moreJun 17, 2026 Apr 23, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A flaw was found in the Ceph Object Gateway, where it supports request sent by an anonymous user in Amazon S3. This flaw could lead to potential XSS attacks due to the lack of proper neutralization of untrusted input. |
2Canonical Linuxfoundation2Ceph Ubuntu LinuxJun 17, 2026 Apr 22, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Ceph through 13.2.9. A POST request with an invalid tagging XML can crash the RGW process by triggering a NULL pointer exception. |
2Linuxfoundation Redhat2Ceph Ceph StorageJun 17, 2026 Apr 21, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A path traversal flaw was found in the Ceph dashboard implemented in upstream versions v14.2.5, v14.2.6, v15.0.0 of Ceph storage and has been fixed in versions 14.2.7 and 15.1.0. An unauthenticated attacker could use thi...Show more |
3Fedoraproject LinuxfoundationRedhat5Ceph Ceph StorageFedora+2 moreJun 17, 2026 Apr 13, 2020 N/A· v4 6.8 MEDIUM· v3 5.8 MEDIUM· v2 A vulnerability was found in Red Hat Ceph Storage 4 and Red Hat Openshift Container Storage 4.2 where, A nonce reuse vulnerability was discovered in the secure mode of the messenger v2 protocol, which can allow an attack...Show more |