A flaw was found in Openstack manilla owning a Ceph File system share, which enables the owner to read/write any manilla share or entire file system. The vulnerability is due to a bug in the volumes plugin in Ceph Manager. This allows an attacker to compromise Confidentiality and Integrity of a file system. Fixed in RHCS 5.2 and Ceph 17.2.2.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Ceph | Linuxfoundation | 15.0.0 (including) | 15.2.17 (excluding) |
Ceph | Linuxfoundation | 16.0.0 (including) | 16.2.10 (excluding) |
Ceph | Linuxfoundation | 17.0.0 (including) | 17.2.2 (excluding) |
Red Hat Ceph Storage 5.2 | RedHat | ceph-2:16.2.8-84.el9cp | * |
Ceph | Ubuntu | focal | * |
Ceph | Ubuntu | jammy | * |
Ceph | Ubuntu | kinetic | * |
Ceph | Ubuntu | trusty | * |
Ceph | Ubuntu | trusty/esm | * |
Ceph | Ubuntu | upstream | * |
Ceph | Ubuntu | xenial | * |