ceph: user/tenant can obtain access (read/write) to any share
Published Jul 25, 2022
9.1
CRITICALCVSS 3.1
EPSS 1.21%
Description
A flaw was found in Openstack manilla owning a Ceph File system "share", which enables the owner to read/write any manilla share or entire file system. The vulnerability is due to a bug in the "volumes" plugin in Ceph Manager. This allows an attacker to compromise Confidentiality and Integrity of a file system. Fixed in RHCS 5.2 and Ceph 17.2.2.
Affected products
- Vendor n/a Product Ceph Defaultn/a
- Version Ceph v 17.2.2StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Ceph | n/a |
|
Configuration 1
- ≥ 15.0.0 · < 15.2.17
- ≥ 16.0.0 · < 16.2.10
- ≥ 17.0.0 · < 17.2.2
Configuration 2
- < 5.2
Configuration 3
- 35
- 36
No data.
Red Hat Ceph Storage 5.2
ceph-2:16.2.8-84.el8cp
Fixed · RHSA-2022:5997
Red Hat Ceph Storage 2
ceph
Out of support scope
Red Hat Ceph Storage 3
ceph
Out of support scope
Red Hat Ceph Storage 4
ceph
Will not fix
Red Hat Enterprise Linux 7
ceph-common
Out of support scope
Red Hat Enterprise Linux 8
ceph
Not affected
Red Hat Enterprise Linux 9
ceph
Not affected
Red Hat OpenStack Platform 13 (Queens)
ceph
Will not fix
Red Hat Openshift Data Foundation 4
ceph
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Ceph Storage 5.2 | ceph-2:16.2.8-84.el8cp | Fixed | RHSA-2022:5997 |
| Red Hat Ceph Storage 2 | ceph | Out of support scope | n/a |
| Red Hat Ceph Storage 3 | ceph | Out of support scope | n/a |
| Red Hat Ceph Storage 4 | ceph | Will not fix | n/a |
| Red Hat Enterprise Linux 7 | ceph-common | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | ceph | Not affected | n/a |
| Red Hat Enterprise Linux 9 | ceph | Not affected | n/a |
| Red Hat OpenStack Platform 13 (Queens) | ceph | Will not fix | n/a |
| Red Hat Openshift Data Foundation 4 | ceph | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat OpenStack Platform deployments use the Ceph package directly from the Ceph channel; the RHOSP package will not be updated at this time.
References (9)
- https://access.redhat.com/security/cve/CVE-2022-0670 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2050728 Issue Tracking
- https://ceph.io/en/news/blog/2022/v17-2-2-quincy-released/ x_refsource_MISCRelease NotesVendor Advisory
- https://docs.ceph.com/en/latest/security/CVE-2022-0670/
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-15759 Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5O3XMDFZWA2FWU6GAYOVSFJPOUTXN42N/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TIRTTRG5O4YP2TNGDCDOHIHP2DM3DFBT/ vendor-advisoryx_refsource_FEDORA
- https://nvd.nist.gov/vuln/detail/CVE-2022-0670
- https://www.cve.org/CVERecord?id=CVE-2022-0670
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2022-0670 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2050728 | Issue Tracking | |
| https://ceph.io/en/news/blog/2022/v17-2-2-quincy-released/ | x_refsource_MISCRelease NotesVendor Advisory | |
| https://docs.ceph.com/en/latest/security/CVE-2022-0670/ | ||
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-15759 | Advisory | |
| https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5O3XMDFZWA2FWU6GAYOVSFJPOUTXN42N/ | vendor-advisoryx_refsource_FEDORA | |
| https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TIRTTRG5O4YP2TNGDCDOHIHP2DM3DFBT/ | vendor-advisoryx_refsource_FEDORA | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-0670 | ||
| https://www.cve.org/CVERecord?id=CVE-2022-0670 |
Change history (0)
No recorded changes yet.