CVE Vulnerabilities

CVE-2022-3650

Placement of User into Incorrect Group

Published: Jan 17, 2023 | Modified: Nov 21, 2024
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
8.8 IMPORTANT
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Ubuntu
MEDIUM

A privilege escalation flaw was found in Ceph. Ceph-crash.service allows a local attacker to escalate privileges to root in the form of a crash dump, and dump privileged information.

Weakness

The product or the administrator places a user into an incorrect group.

Affected Software

Name Vendor Start Version End Version
Ceph Redhat 16.2.9 (including) 16.2.9 (including)
Ceph Ubuntu devel *
Ceph Ubuntu esm-infra-legacy/trusty *
Ceph Ubuntu focal *
Ceph Ubuntu jammy *
Ceph Ubuntu kinetic *
Ceph Ubuntu lunar *
Ceph Ubuntu mantic *
Ceph Ubuntu noble *
Ceph Ubuntu oracular *
Ceph Ubuntu trusty *
Ceph Ubuntu trusty/esm *
Ceph Ubuntu upstream *
Ceph Ubuntu xenial *
Red Hat Ceph Storage 5.3 RedHat ceph-2:16.2.10-138.el9cp *

References