CVE-2022-0670
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
25/07/2022
Last modified:
07/11/2023
Description
A flaw was found in Openstack manilla owning a Ceph File system "share", which enables the owner to read/write any manilla share or entire file system. The vulnerability is due to a bug in the "volumes" plugin in Ceph Manager. This allows an attacker to compromise Confidentiality and Integrity of a file system. Fixed in RHCS 5.2 and Ceph 17.2.2.
Impact
Base Score 3.x
9.10
Severity 3.x
CRITICAL
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:linuxfoundation:ceph:*:*:*:*:*:*:*:* | 15.0.0 (including) | 15.2.17 (excluding) |
| cpe:2.3:a:linuxfoundation:ceph:*:*:*:*:*:*:*:* | 16.0.0 (including) | 16.2.10 (excluding) |
| cpe:2.3:a:linuxfoundation:ceph:*:*:*:*:*:*:*:* | 17.0.0 (including) | 17.2.2 (excluding) |
| cpe:2.3:a:redhat:ceph_storage:*:*:*:*:*:*:*:* | 5.2 (excluding) | |
| cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:* | ||
| cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://ceph.io/en/news/blog/2022/v17-2-2-quincy-released/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5O3XMDFZWA2FWU6GAYOVSFJPOUTXN42N/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TIRTTRG5O4YP2TNGDCDOHIHP2DM3DFBT/



