Description
A flaw was found in Openstack manilla owning a Ceph File system "share", which enables the owner to read/write any manilla share or entire file system. The vulnerability is due to a bug in the "volumes" plugin in Ceph Manager. This allows an attacker to compromise Confidentiality and Integrity of a file system. Fixed in RHCS 5.2 and Ceph 17.2.2.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-4460-1 | ceph security update |
EUVD |
EUVD-2022-15759 | A flaw was found in Openstack manilla owning a Ceph File system "share", which enables the owner to read/write any manilla share or entire file system. The vulnerability is due to a bug in the "volumes" plugin in Ceph Manager. This allows an attacker to compromise Confidentiality and Integrity of a file system. Fixed in RHCS 5.2 and Ceph 17.2.2. |
Ubuntu USN |
USN-6063-1 | Ceph vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-02T23:32:46.554Z
Reserved: 2022-02-17T00:00:00.000Z
Link: CVE-2022-0670
No data.
Status : Modified
Published: 2022-07-25T14:15:10.327
Modified: 2024-11-21T06:39:09.053
Link: CVE-2022-0670
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
EUVD
Ubuntu USN