Back

CRITICAL

ceph: user/tenant can obtain access (read/write) to any share

Published Jul 25, 2022

Description

A flaw was found in Openstack manilla owning a Ceph File system "share", which enables the owner to read/write any manilla share or entire file system. The vulnerability is due to a bug in the "volumes" plugin in Ceph Manager. This allows an attacker to compromise Confidentiality and Integrity of a file system. Fixed in RHCS 5.2 and Ceph 17.2.2.

Affected products

Remediation

Red Hat statement

Red Hat OpenStack Platform deployments use the Ceph package directly from the Ceph channel; the RHOSP package will not be updated at this time.

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jul 25, 2022
Updated Aug 2, 2024
Reserved Feb 17, 2022
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Jul 21, 2022
ENISA EUVD
Assigner redhat
Published Jul 25, 2022
Updated Aug 2, 2024
Exploited since n/a
EUVD-2022-15759