Записи ceph
11 опубликованных записей вендора ceph.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 100 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-284 Improper Access Control1
- CWE-285 Improper Authorization1
- CWE-306 Missing Authentication for Critical Function1
- CWE-312 Cleartext Storage of Sensitive Information1
- CWE-400 Uncontrolled Resource Consumption1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
11 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
35Наблюдать | CVE-2020-1716Эксплойта нет | A flaw was found in the ceph-ansible playbook where it contained hardcoded passwords that were being used as default passwords while deployiceph · ceph-ansible · CWE-798 | Высокая8,8 | — | 1,3 % | 28 мая 2021 г. |
33Наблюдать | CVE-2018-10861Эксплойта нет | A flaw was found in the way ceph mon handles user requests.ceph · ceph · CWE-285 | Высокая8,1 | — | 3,2 % | 10 июл. 2018 г. |
31Наблюдать | CVE-2019-10222Эксплойта нет | A flaw was found in the Ceph RGW configuration with Beast as the front end handling client requests.ceph · ceph · CWE-755 | Высокая7,5 | — | 4,5 % | 8 нояб. 2019 г. |
31Наблюдать | CVE-2019-3821Эксплойта нет | A flaw was found in the way civetweb frontend was handling requests for ceph RGW server with SSL enabled.ceph · civetweb · CWE-772 | Высокая7,5 | — | 2,9 % | 27 мар. 2019 г. |
27Наблюдать | CVE-2020-1700Эксплойта нет | A flaw was found in the way the Ceph RGW Beast front-end handles unexpected disconnects.ceph · ceph · CWE-400 | Средняя6,5 | — | 2,4 % | 7 февр. 2020 г. |
27Наблюдать | CVE-2018-1129Эксплойта нет | A flaw was found in the way signature calculation was handled by cephx authentication protocol.ceph · ceph · CWE-284 | Средняя6,5 | — | 1,9 % | 10 июл. 2018 г. |
25Наблюдать | CVE-2017-12155Эксплойта нет | A resource-permission flaw was found in the openstack-tripleo-heat-templates package where ceph.client.openstack.keyring is created as worldceph · ceph · CWE-306 | Средняя6,3 | — | 0,3 % | 12 дек. 2017 г. |
22Наблюдать | CVE-2020-25677Эксплойта нет | A flaw was found in Ceph-ansible v4.0.41 where it creates an /etc/ceph/iscsi-gateway.conf with insecure default permissions.ceph · ceph-ansible · CWE-312 | Средняя5,5 | — | 0,2 % | 7 дек. 2020 г. |
17Наблюдать | CVE-2017-7519Эксплойта нет | In Ceph, a format string flaw was found in the way libradosstriper parses input from user.ceph · ceph · CWE-134 | Средняя4,4 | — | 0,5 % | 27 июл. 2018 г. |
8Наблюдать | CVE-2015-4053Эксплойта нет | The admin command in ceph-deploy before 1.5.25 uses world-readable permissions for /etc/ceph/ceph.client.admin.keyring, which allows local uceph · ceph-deploy · CWE-200 | Низкая2,1 | — | 0,4 % | 8 июн. 2015 г. |
8Наблюдать | CVE-2015-3010Эксплойта нет | ceph-deploy before 1.5.23 uses weak permissions (644) for ceph/ceph.client.admin.keyring, which allows local users to obtain sensitive inforceph · ceph-deploy · CWE-200 | Низкая2,1 | — | 0,4 % | 16 июн. 2015 г. |
- CVE-2020-171635Наблюдать
A flaw was found in the ceph-ansible playbook where it contained hardcoded passwords that were being used as default passwords while deployi
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %ceph · ceph-ansible28 мая 2021 г.
- CVE-2018-1086133Наблюдать
A flaw was found in the way ceph mon handles user requests.
ВысокаяCVSS 8,1Эксплойта нетEPSS 3 %ceph · ceph10 июл. 2018 г.
- CVE-2019-1022231Наблюдать
A flaw was found in the Ceph RGW configuration with Beast as the front end handling client requests.
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %ceph · ceph8 нояб. 2019 г.
- CVE-2019-382131Наблюдать
A flaw was found in the way civetweb frontend was handling requests for ceph RGW server with SSL enabled.
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %ceph · civetweb27 мар. 2019 г.
- CVE-2020-170027Наблюдать
A flaw was found in the way the Ceph RGW Beast front-end handles unexpected disconnects.
СредняяCVSS 6,5Эксплойта нетEPSS 2 %ceph · ceph7 февр. 2020 г.
- CVE-2018-112927Наблюдать
A flaw was found in the way signature calculation was handled by cephx authentication protocol.
СредняяCVSS 6,5Эксплойта нетEPSS 2 %ceph · ceph10 июл. 2018 г.
- CVE-2017-1215525Наблюдать
A resource-permission flaw was found in the openstack-tripleo-heat-templates package where ceph.client.openstack.keyring is created as world
СредняяCVSS 6,3Эксплойта нетEPSS 0 %ceph · ceph12 дек. 2017 г.
- CVE-2020-2567722Наблюдать
A flaw was found in Ceph-ansible v4.0.41 where it creates an /etc/ceph/iscsi-gateway.conf with insecure default permissions.
СредняяCVSS 5,5Эксплойта нетEPSS 0 %ceph · ceph-ansible7 дек. 2020 г.
- CVE-2017-751917Наблюдать
In Ceph, a format string flaw was found in the way libradosstriper parses input from user.
СредняяCVSS 4,4Эксплойта нетEPSS 1 %ceph · ceph27 июл. 2018 г.
- CVE-2015-40538Наблюдать
The admin command in ceph-deploy before 1.5.25 uses world-readable permissions for /etc/ceph/ceph.client.admin.keyring, which allows local u
НизкаяCVSS 2,1Эксплойта нетEPSS 0 %ceph · ceph-deploy8 июн. 2015 г.
- CVE-2015-30108Наблюдать
ceph-deploy before 1.5.23 uses weak permissions (644) for ceph/ceph.client.admin.keyring, which allows local users to obtain sensitive infor
НизкаяCVSS 2,1Эксплойта нетEPSS 0 %ceph · ceph-deploy16 июн. 2015 г.