ceph records
11 published records for vendor ceph.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-284 Improper Access Control1
- CWE-285 Improper Authorization1
- CWE-306 Missing Authentication for Critical Function1
- CWE-312 Cleartext Storage of Sensitive Information1
- CWE-400 Uncontrolled Resource Consumption1
The weakness classes this vendor ships most often: where to look.
CWEAll records
11 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
35Monitor | CVE-2020-1716No exploit | A flaw was found in the ceph-ansible playbook where it contained hardcoded passwords that were being used as default passwords while deployiceph · ceph-ansible · CWE-798 | High8.8 | — | 1.3% | May 28, 2021 |
33Monitor | CVE-2018-10861No exploit | A flaw was found in the way ceph mon handles user requests.ceph · ceph · CWE-285 | High8.1 | — | 3.2% | Jul 10, 2018 |
31Monitor | CVE-2019-10222No exploit | A flaw was found in the Ceph RGW configuration with Beast as the front end handling client requests.ceph · ceph · CWE-755 | High7.5 | — | 4.5% | Nov 8, 2019 |
31Monitor | CVE-2019-3821No exploit | A flaw was found in the way civetweb frontend was handling requests for ceph RGW server with SSL enabled.ceph · civetweb · CWE-772 | High7.5 | — | 2.9% | Mar 27, 2019 |
27Monitor | CVE-2020-1700No exploit | A flaw was found in the way the Ceph RGW Beast front-end handles unexpected disconnects.ceph · ceph · CWE-400 | Medium6.5 | — | 2.4% | Feb 7, 2020 |
27Monitor | CVE-2018-1129No exploit | A flaw was found in the way signature calculation was handled by cephx authentication protocol.ceph · ceph · CWE-284 | Medium6.5 | — | 1.9% | Jul 10, 2018 |
25Monitor | CVE-2017-12155No exploit | A resource-permission flaw was found in the openstack-tripleo-heat-templates package where ceph.client.openstack.keyring is created as worldceph · ceph · CWE-306 | Medium6.3 | — | 0.3% | Dec 12, 2017 |
22Monitor | CVE-2020-25677No exploit | A flaw was found in Ceph-ansible v4.0.41 where it creates an /etc/ceph/iscsi-gateway.conf with insecure default permissions.ceph · ceph-ansible · CWE-312 | Medium5.5 | — | 0.2% | Dec 7, 2020 |
17Monitor | CVE-2017-7519No exploit | In Ceph, a format string flaw was found in the way libradosstriper parses input from user.ceph · ceph · CWE-134 | Medium4.4 | — | 0.5% | Jul 27, 2018 |
8Monitor | CVE-2015-4053No exploit | The admin command in ceph-deploy before 1.5.25 uses world-readable permissions for /etc/ceph/ceph.client.admin.keyring, which allows local uceph · ceph-deploy · CWE-200 | Low2.1 | — | 0.4% | Jun 8, 2015 |
8Monitor | CVE-2015-3010No exploit | ceph-deploy before 1.5.23 uses weak permissions (644) for ceph/ceph.client.admin.keyring, which allows local users to obtain sensitive inforceph · ceph-deploy · CWE-200 | Low2.1 | — | 0.4% | Jun 16, 2015 |
- CVE-2020-171635Monitor
A flaw was found in the ceph-ansible playbook where it contained hardcoded passwords that were being used as default passwords while deployi
HighCVSS 8.8No exploitEPSS 1%ceph · ceph-ansibleMay 28, 2021
- CVE-2018-1086133Monitor
A flaw was found in the way ceph mon handles user requests.
HighCVSS 8.1No exploitEPSS 3%ceph · cephJul 10, 2018
- CVE-2019-1022231Monitor
A flaw was found in the Ceph RGW configuration with Beast as the front end handling client requests.
HighCVSS 7.5No exploitEPSS 4%ceph · cephNov 8, 2019
- CVE-2019-382131Monitor
A flaw was found in the way civetweb frontend was handling requests for ceph RGW server with SSL enabled.
HighCVSS 7.5No exploitEPSS 3%ceph · civetwebMar 27, 2019
- CVE-2020-170027Monitor
A flaw was found in the way the Ceph RGW Beast front-end handles unexpected disconnects.
MediumCVSS 6.5No exploitEPSS 2%ceph · cephFeb 7, 2020
- CVE-2018-112927Monitor
A flaw was found in the way signature calculation was handled by cephx authentication protocol.
MediumCVSS 6.5No exploitEPSS 2%ceph · cephJul 10, 2018
- CVE-2017-1215525Monitor
A resource-permission flaw was found in the openstack-tripleo-heat-templates package where ceph.client.openstack.keyring is created as world
MediumCVSS 6.3No exploitEPSS 0%ceph · cephDec 12, 2017
- CVE-2020-2567722Monitor
A flaw was found in Ceph-ansible v4.0.41 where it creates an /etc/ceph/iscsi-gateway.conf with insecure default permissions.
MediumCVSS 5.5No exploitEPSS 0%ceph · ceph-ansibleDec 7, 2020
- CVE-2017-751917Monitor
In Ceph, a format string flaw was found in the way libradosstriper parses input from user.
MediumCVSS 4.4No exploitEPSS 1%ceph · cephJul 27, 2018
- CVE-2015-40538Monitor
The admin command in ceph-deploy before 1.5.25 uses world-readable permissions for /etc/ceph/ceph.client.admin.keyring, which allows local u
LowCVSS 2.1No exploitEPSS 0%ceph · ceph-deployJun 8, 2015
- CVE-2015-30108Monitor
ceph-deploy before 1.5.23 uses weak permissions (644) for ceph/ceph.client.admin.keyring, which allows local users to obtain sensitive infor
LowCVSS 2.1No exploitEPSS 0%ceph · ceph-deployJun 16, 2015