Skip to content
Noroxi

ceph records

11 published records for vendor ceph.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
100%
Median publish → KEV
No record has entered KEV

All records

11 records
  • CVE-2020-1716
    35Monitor

    A flaw was found in the ceph-ansible playbook where it contained hardcoded passwords that were being used as default passwords while deployi

    HighCVSS 8.8No exploitEPSS 1%

    ceph · ceph-ansibleMay 28, 2021

  • A flaw was found in the way ceph mon handles user requests.

    HighCVSS 8.1No exploitEPSS 3%

    ceph · cephJul 10, 2018

  • A flaw was found in the Ceph RGW configuration with Beast as the front end handling client requests.

    HighCVSS 7.5No exploitEPSS 4%

    ceph · cephNov 8, 2019

  • CVE-2019-3821
    31Monitor

    A flaw was found in the way civetweb frontend was handling requests for ceph RGW server with SSL enabled.

    HighCVSS 7.5No exploitEPSS 3%

    ceph · civetwebMar 27, 2019

  • CVE-2020-1700
    27Monitor

    A flaw was found in the way the Ceph RGW Beast front-end handles unexpected disconnects.

    MediumCVSS 6.5No exploitEPSS 2%

    ceph · cephFeb 7, 2020

  • CVE-2018-1129
    27Monitor

    A flaw was found in the way signature calculation was handled by cephx authentication protocol.

    MediumCVSS 6.5No exploitEPSS 2%

    ceph · cephJul 10, 2018

  • A resource-permission flaw was found in the openstack-tripleo-heat-templates package where ceph.client.openstack.keyring is created as world

    MediumCVSS 6.3No exploitEPSS 0%

    ceph · cephDec 12, 2017

  • A flaw was found in Ceph-ansible v4.0.41 where it creates an /etc/ceph/iscsi-gateway.conf with insecure default permissions.

    MediumCVSS 5.5No exploitEPSS 0%

    ceph · ceph-ansibleDec 7, 2020

  • CVE-2017-7519
    17Monitor

    In Ceph, a format string flaw was found in the way libradosstriper parses input from user.

    MediumCVSS 4.4No exploitEPSS 1%

    ceph · cephJul 27, 2018

  • The admin command in ceph-deploy before 1.5.25 uses world-readable permissions for /etc/ceph/ceph.client.admin.keyring, which allows local u

    LowCVSS 2.1No exploitEPSS 0%

    ceph · ceph-deployJun 8, 2015

  • ceph-deploy before 1.5.23 uses weak permissions (644) for ceph/ceph.client.admin.keyring, which allows local users to obtain sensitive infor

    LowCVSS 2.1No exploitEPSS 0%

    ceph · ceph-deployJun 16, 2015