SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2018-10861

Any authenticated ceph user having read access to ceph can delete, create ceph storage pools and corrupt snapshot images.

HIGH 8.1EPSS 3.22%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (3.22%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

A flaw was found in the way ceph mon handles user requests. Any authenticated ceph user having read access to ceph can delete, create ceph storage pools and corrupt snapshot images. Ceph branches master, mimic, luminous and jewel are believed to be affected.

CVSS 3.0
8.1 HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
EPSS
3.22% probability · 88th percentile
CISA KEV
Not listed
Weakness
CWE-285, CWE-287
Affected
ceph/ceph · redhat/ceph storage · redhat/ceph storage mon · redhat/ceph storage osd · redhat/enterprise linux desktop · redhat/enterprise linux server · redhat/enterprise linux workstation · opensuse/leap · debian/debian linux
Source
secalert@redhat.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.