[Bugs] [Bug 13502] New: [CVE 21] ceph 15.2.7 CVEs found

bugzilla bugzilla на rosalinux.ru
Ср Авг 23 23:18:12 MSK 2023


https://bugzilla.rosalinux.ru/show_bug.cgi?id=13502

          Platform: 2021.1
            Bug ID: 13502
           Summary: [CVE 21] ceph 15.2.7  CVEs found
    Classification: ROSA-based products
           Product: ROSA Fresh
           Version: All
          Hardware: All
               URL: CVE-2020-25678, CVE-2020-27781, CVE-2020-27839,
                    CVE-2022-0670,
                OS: Linux
            Status: CONFIRMED
          Severity: normal
          Priority: Normal
         Component: System (kernel, glibc, systemd, bash, PAM...)
          Assignee: bugs на lists.rosalinux.ru
          Reporter: y.tumanov на rosalinux.ru
        QA Contact: bugs на lists.rosalinux.ru
                CC: e.kosachev на rosalinux.ru, s.matveev на rosalinux.ru,
                    y.tumanov на rosalinux.ru
  Target Milestone: ---
             Flags: secteam_verified?

Please patch CVEs for package ceph version 15.2.7

INFO (CVEs are): ceph 15.2.7
 cves found
CVE-2020-25678
Desc: A flaw was found in ceph in versions prior to 16.y.z where ceph stores
mgr module passwords in clear text. This can be found by searching the mgr logs
for grafana and dashboard, with passwords visible.
Link: https://nvd.nist.gov/vuln/detail/CVE-2020-25678
Severity: MEDIUM
CVE-2020-27781
Desc: User credentials can be manipulated and stolen by Native CephFS consumers
of OpenStack Manila, resulting in potential privilege escalation. An Open Stack
Manila user can request access to a share to an arbitrary cephx user, including
existing users. The access key is retrieved via the interface drivers. Then,
all users of the requesting OpenStack project can view the access key. This
enables the attacker to target any resource that the user has access to. This
can be done to even "admin" users, compromising the ceph administrator. This
flaw affects Ceph versions prior to 14.2.16, 15.x prior to 15.2.8, and 16.x
prior to 16.2.0.
Link: https://nvd.nist.gov/vuln/detail/CVE-2020-27781
Severity: HIGH
CVE-2020-27839
Desc: A flaw was found in ceph-dashboard. The JSON Web Token (JWT) used for
user authentication is stored by the frontend application in the browser’s
localStorage which is potentially vulnerable to attackers via XSS attacks. The
highest threat from this vulnerability is to data confidentiality and
integrity.
Link: https://nvd.nist.gov/vuln/detail/CVE-2020-27839
Severity: MEDIUM
CVE-2022-0670
Desc: A flaw was found in Openstack manilla owning a Ceph File system "share",
which enables the owner to read/write any manilla share or entire file system.
The vulnerability is due to a bug in the "volumes" plugin in Ceph Manager. This
allows an attacker to compromise Confidentiality and Integrity of a file
system. Fixed in RHCS 5.2 and Ceph 17.2.2.
Link: https://nvd.nist.gov/vuln/detail/CVE-2022-0670
Severity: CRITICAL

-- 
You are receiving this mail because:
You are the QA Contact for the bug.
You are the assignee for the bug.
----------- следущая часть -----------
Вложение в формате HTML было извлечено…
URL: <http://lists.rosalinux.ru/pipermail/bugs/attachments/20230823/08be699e/attachment.html>


Подробная информация о списке рассылки Bugs