Linux / Ceph
8 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2022-0670 | ceph: user/tenant can obtain access (read/write) to any share | CRITICAL | 9.1 | Jul 25, 2022 |
| CVE-2021-20288 | ceph: Unauthorized global_id reuse in cephx | HIGH | 8.0 | Apr 15, 2021 |
| CVE-2020-10753 | ceph: radosgw: HTTP header injection via CORS ExposeHeader tag | MEDIUM | 6.5 | Jun 26, 2020 |
| CVE-2020-10736 | ceph: authorization bypass in monitor and manager daemons | HIGH | 8.0 | Jun 22, 2020 |
| CVE-2020-1760 | ceph: header-splitting in RGW GetObject has a possible XSS | MEDIUM | 6.1 | Apr 23, 2020 |
| CVE-2020-12059 | ceph: specially crafted XML payload on POST requests leads to DoS by crashing RGW | HIGH | 7.5 | Apr 22, 2020 |
| CVE-2020-1699 | ceph: improper URL checking leads to information disclosure | HIGH | 7.5 | Apr 21, 2020 |
| CVE-2020-1759 | ceph: secure mode of msgr2 breaks both confidentiality and integrity aspects for long-lived sessions | MEDIUM | 6.8 | Apr 13, 2020 |
Showing 1 to 8 of 8 CVEs