CVE-2022-0670

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
25/07/2022
Last modified:
07/11/2023

Description

A flaw was found in Openstack manilla owning a Ceph File system "share", which enables the owner to read/write any manilla share or entire file system. The vulnerability is due to a bug in the "volumes" plugin in Ceph Manager. This allows an attacker to compromise Confidentiality and Integrity of a file system. Fixed in RHCS 5.2 and Ceph 17.2.2.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:linuxfoundation:ceph:*:*:*:*:*:*:*:* 15.0.0 (including) 15.2.17 (excluding)
cpe:2.3:a:linuxfoundation:ceph:*:*:*:*:*:*:*:* 16.0.0 (including) 16.2.10 (excluding)
cpe:2.3:a:linuxfoundation:ceph:*:*:*:*:*:*:*:* 17.0.0 (including) 17.2.2 (excluding)
cpe:2.3:a:redhat:ceph_storage:*:*:*:*:*:*:*:* 5.2 (excluding)
cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*