Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2020-27781


User credentials can be manipulated and stolen by Native CephFS consumers of OpenStack Manila, resulting in potential privilege escalation. An Open Stack Manila user can request access to a share to an arbitrary cephx user, including existing users. The access key is retrieved via the interface drivers. Then, all users of the requesting OpenStack project can view the access key. This enables the attacker to target any resource that the user has access to. This can be done to even "admin" users, compromising the ceph administrator. This flaw affects Ceph versions prior to 14.2.16, 15.x prior to 15.2.8, and 16.x prior to 16.2.0.


Published

2020-12-18T21:15:12.660

Last Modified

2024-11-21T05:21:49.417

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.1 (HIGH)

CVSSv2 Vector

AV:L/AC:L/Au:N/C:P/I:P/A:N

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

3.9

Impact Score

4.9

Weaknesses
  • Type: Secondary
    CWE-522
  • Type: Primary
    CWE-522

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application redhat ceph < 14.2.16 Yes
Application redhat ceph < 15.2.8 Yes
Application redhat ceph < 16.2.0 Yes
Application redhat ceph_storage 2.0 Yes
Application redhat ceph_storage 3.0 Yes
Application redhat ceph_storage 4.0 Yes
Application redhat openshift_container_platform 4.0 Yes
Application redhat openstack_platform 13.0 Yes
Operating System fedoraproject fedora 33 Yes

References