ceph kayıtları
ceph üreticisine ait 11 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %100
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-284 Improper Access Control1
- CWE-285 Improper Authorization1
- CWE-306 Missing Authentication for Critical Function1
- CWE-312 Cleartext Storage of Sensitive Information1
- CWE-400 Uncontrolled Resource Consumption1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
11 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
35İzleyin | CVE-2020-1716İstismar yok | A flaw was found in the ceph-ansible playbook where it contained hardcoded passwords that were being used as default passwords while deployiceph · ceph-ansible · CWE-798 | Yüksek8,8 | — | %1,3 | 28 May 2021 |
33İzleyin | CVE-2018-10861İstismar yok | A flaw was found in the way ceph mon handles user requests.ceph · ceph · CWE-285 | Yüksek8,1 | — | %3,2 | 10 Tem 2018 |
31İzleyin | CVE-2019-10222İstismar yok | A flaw was found in the Ceph RGW configuration with Beast as the front end handling client requests.ceph · ceph · CWE-755 | Yüksek7,5 | — | %4,5 | 8 Kas 2019 |
31İzleyin | CVE-2019-3821İstismar yok | A flaw was found in the way civetweb frontend was handling requests for ceph RGW server with SSL enabled.ceph · civetweb · CWE-772 | Yüksek7,5 | — | %2,9 | 27 Mar 2019 |
27İzleyin | CVE-2020-1700İstismar yok | A flaw was found in the way the Ceph RGW Beast front-end handles unexpected disconnects.ceph · ceph · CWE-400 | Orta6,5 | — | %2,4 | 7 Şub 2020 |
27İzleyin | CVE-2018-1129İstismar yok | A flaw was found in the way signature calculation was handled by cephx authentication protocol.ceph · ceph · CWE-284 | Orta6,5 | — | %1,9 | 10 Tem 2018 |
25İzleyin | CVE-2017-12155İstismar yok | A resource-permission flaw was found in the openstack-tripleo-heat-templates package where ceph.client.openstack.keyring is created as worldceph · ceph · CWE-306 | Orta6,3 | — | %0,3 | 12 Ara 2017 |
22İzleyin | CVE-2020-25677İstismar yok | A flaw was found in Ceph-ansible v4.0.41 where it creates an /etc/ceph/iscsi-gateway.conf with insecure default permissions.ceph · ceph-ansible · CWE-312 | Orta5,5 | — | %0,2 | 7 Ara 2020 |
17İzleyin | CVE-2017-7519İstismar yok | In Ceph, a format string flaw was found in the way libradosstriper parses input from user.ceph · ceph · CWE-134 | Orta4,4 | — | %0,5 | 27 Tem 2018 |
8İzleyin | CVE-2015-4053İstismar yok | The admin command in ceph-deploy before 1.5.25 uses world-readable permissions for /etc/ceph/ceph.client.admin.keyring, which allows local uceph · ceph-deploy · CWE-200 | Düşük2,1 | — | %0,4 | 8 Haz 2015 |
8İzleyin | CVE-2015-3010İstismar yok | ceph-deploy before 1.5.23 uses weak permissions (644) for ceph/ceph.client.admin.keyring, which allows local users to obtain sensitive inforceph · ceph-deploy · CWE-200 | Düşük2,1 | — | %0,4 | 16 Haz 2015 |
- CVE-2020-171635İzleyin
A flaw was found in the ceph-ansible playbook where it contained hardcoded passwords that were being used as default passwords while deployi
YüksekCVSS 8,8İstismar yokEPSS %1ceph · ceph-ansible28 May 2021
- CVE-2018-1086133İzleyin
A flaw was found in the way ceph mon handles user requests.
YüksekCVSS 8,1İstismar yokEPSS %3ceph · ceph10 Tem 2018
- CVE-2019-1022231İzleyin
A flaw was found in the Ceph RGW configuration with Beast as the front end handling client requests.
YüksekCVSS 7,5İstismar yokEPSS %4ceph · ceph8 Kas 2019
- CVE-2019-382131İzleyin
A flaw was found in the way civetweb frontend was handling requests for ceph RGW server with SSL enabled.
YüksekCVSS 7,5İstismar yokEPSS %3ceph · civetweb27 Mar 2019
- CVE-2020-170027İzleyin
A flaw was found in the way the Ceph RGW Beast front-end handles unexpected disconnects.
OrtaCVSS 6,5İstismar yokEPSS %2ceph · ceph7 Şub 2020
- CVE-2018-112927İzleyin
A flaw was found in the way signature calculation was handled by cephx authentication protocol.
OrtaCVSS 6,5İstismar yokEPSS %2ceph · ceph10 Tem 2018
- CVE-2017-1215525İzleyin
A resource-permission flaw was found in the openstack-tripleo-heat-templates package where ceph.client.openstack.keyring is created as world
OrtaCVSS 6,3İstismar yokEPSS %0ceph · ceph12 Ara 2017
- CVE-2020-2567722İzleyin
A flaw was found in Ceph-ansible v4.0.41 where it creates an /etc/ceph/iscsi-gateway.conf with insecure default permissions.
OrtaCVSS 5,5İstismar yokEPSS %0ceph · ceph-ansible7 Ara 2020
- CVE-2017-751917İzleyin
In Ceph, a format string flaw was found in the way libradosstriper parses input from user.
OrtaCVSS 4,4İstismar yokEPSS %1ceph · ceph27 Tem 2018
- CVE-2015-40538İzleyin
The admin command in ceph-deploy before 1.5.25 uses world-readable permissions for /etc/ceph/ceph.client.admin.keyring, which allows local u
DüşükCVSS 2,1İstismar yokEPSS %0ceph · ceph-deploy8 Haz 2015
- CVE-2015-30108İzleyin
ceph-deploy before 1.5.23 uses weak permissions (644) for ceph/ceph.client.admin.keyring, which allows local users to obtain sensitive infor
DüşükCVSS 2,1İstismar yokEPSS %0ceph · ceph-deploy16 Haz 2015