CVE Vulnerabilities

CVE-2022-0670

Published: Jul 25, 2022 | Modified: Nov 07, 2023
CVSS 3.x
9.1
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A flaw was found in Openstack manilla owning a Ceph File system share, which enables the owner to read/write any manilla share or entire file system. The vulnerability is due to a bug in the volumes plugin in Ceph Manager. This allows an attacker to compromise Confidentiality and Integrity of a file system. Fixed in RHCS 5.2 and Ceph 17.2.2.

Affected Software

Name Vendor Start Version End Version
Ceph Linuxfoundation 15.0.0 (including) 15.2.17 (excluding)
Ceph Linuxfoundation 16.0.0 (including) 16.2.10 (excluding)
Ceph Linuxfoundation 17.0.0 (including) 17.2.2 (excluding)

References