ceph: authenticated user with read only permissions can steal dm-crypt / LUKS key
Published Jan 15, 2019
5.7
MEDIUMCVSS 3.1
EPSS 0.49%
Description
It was found Ceph versions before 13.2.4 that authenticated ceph users with read only permissions could steal dm-crypt encryption keys used in ceph disk encryption.
Affected products
- Vendor n/a Product Ceph Defaultn/a
- Version 13.2.4StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Ceph | n/a |
|
Configuration 2
- 8.0
- 9.0
Configuration 4
- 2.0
- 3.0
- 7.0
Configuration 5
- 16.04
- 18.10
- 19.04
No data.
Red Hat Ceph Storage 3 for Ubuntu
ceph
Fixed · RHSA-2019:2541
Red Hat Ceph Storage 3.3
ceph-2:12.2.12-45.el7cp
Fixed · RHSA-2019:2538
Red Hat Ceph Storage 3.3
ceph-ansible-0:3.2.24-1.el7cp
Fixed · RHSA-2019:2538
Red Hat Ceph Storage 3.3
ceph-iscsi-config-0:2.6-19.el7cp
Fixed · RHSA-2019:2538
Red Hat Ceph Storage 3.3
cephmetrics-0:2.0.6-1.el7cp
Fixed · RHSA-2019:2538
Red Hat Ceph Storage 3.3
libntirpc-0:1.7.4-1.el7cp
Fixed · RHSA-2019:2538
Red Hat Ceph Storage 3.3
nfs-ganesha-0:2.7.4-10.el7cp
Fixed · RHSA-2019:2538
Red Hat Ceph Storage 3.3
python-crypto-0:2.6.1-16.el7ost
Fixed · RHSA-2019:2538
Red Hat Ceph Storage 2
ceph
Affected
Red Hat Enterprise Linux 7
ceph-common
Not affected
Red Hat Enterprise Linux 8
ceph
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Ceph Storage 3 for Ubuntu | ceph | Fixed | RHSA-2019:2541 |
| Red Hat Ceph Storage 3.3 | ceph-2:12.2.12-45.el7cp | Fixed | RHSA-2019:2538 |
| Red Hat Ceph Storage 3.3 | ceph-ansible-0:3.2.24-1.el7cp | Fixed | RHSA-2019:2538 |
| Red Hat Ceph Storage 3.3 | ceph-iscsi-config-0:2.6-19.el7cp | Fixed | RHSA-2019:2538 |
| Red Hat Ceph Storage 3.3 | cephmetrics-0:2.0.6-1.el7cp | Fixed | RHSA-2019:2538 |
| Red Hat Ceph Storage 3.3 | libntirpc-0:1.7.4-1.el7cp | Fixed | RHSA-2019:2538 |
| Red Hat Ceph Storage 3.3 | nfs-ganesha-0:2.7.4-10.el7cp | Fixed | RHSA-2019:2538 |
| Red Hat Ceph Storage 3.3 | python-crypto-0:2.6.1-16.el7ost | Fixed | RHSA-2019:2538 |
| Red Hat Ceph Storage 2 | ceph | Affected | n/a |
| Red Hat Enterprise Linux 7 | ceph-common | Not affected | n/a |
| Red Hat Enterprise Linux 8 | ceph | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (12)
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00100.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2538 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2541 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2018-14662 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1637327 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14662 x_refsource_CONFIRMIssue TrackingPatchThird Party Advisory
- https://ceph.com/releases/13-2-4-mimic-released x_refsource_MISCVendor Advisory
- https://lists.debian.org/debian-lts-announce/2019/03/msg00002.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/08/msg00013.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2018-14662
- https://usn.ubuntu.com/4035-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2018-14662
Change history (0)
No recorded changes yet.