An authorization bypass vulnerability was found in Ceph versions 15.2.0 before 15.2.2, where the ceph-mon and ceph-mgr daemons do not properly restrict access, resulting in gaining access to unauthorized resources. This flaw allows an authenticated client to modify the configuration and possibly conduct further attacks.
2020-06-22T18:15:10.993
2024-11-21T04:55:57.890
Modified
CVSSv3.1: 8.0 (HIGH)
AV:A/AC:L/Au:S/C:P/I:P/A:P
5.1
6.4
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | linuxfoundation | ceph | < 15.2.2 | Yes |