CVE-2021-20288
Description
An authentication flaw was found in ceph in versions before 14.2.20. When the monitor handles CEPHX_GET_AUTH_SESSION_KEY requests, it doesnt sanitize other_keys, allowing key reuse. An attacker who can request a global_id can exploit the ability of any user to request a global_id previously associated with another user, as ceph does not force the reuse of old keys to generate new ones. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Risk Information
Base Score
7.2
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.179
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| (RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update ceph-ansible-4.0.57-1.el7cp.noarch.rpm | Linux |
| (RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update ceph-ansible-4.0.57-1.el8cp.noarch.rpm | Linux |
| (RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update ceph-base-14.2.11-181.el7cp.x86_64.rpm | Linux |
| (RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update ceph-base-14.2.11-181.el8cp.x86_64.rpm | Linux |
| (RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update ceph-common-14.2.11-181.el7cp.x86_64.rpm | Linux |
| (RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update ceph-common-14.2.11-181.el8cp.x86_64.rpm | Linux |
| (RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update ceph-debugsource-14.2.11-181.el8cp.x86_64.rpm | Linux |
| (RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update ceph-fuse-14.2.11-181.el7cp.x86_64.rpm | Linux |
| (RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update ceph-fuse-14.2.11-181.el8cp.x86_64.rpm | Linux |
| (RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update ceph-grafana-dashboards-14.2.11-181.el7cp.noarch.rpm | Linux |
| (RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update ceph-grafana-dashboards-14.2.11-181.el8cp.noarch.rpm | Linux |
| (RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update ceph-iscsi-3.4-4.el7cp.noarch.rpm | Linux |
| (RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update ceph-iscsi-3.4-4.el8cp.noarch.rpm | Linux |
| (RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update ceph-mds-14.2.11-181.el7cp.x86_64.rpm | Linux |
| (RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update ceph-mds-14.2.11-181.el8cp.x86_64.rpm | Linux |
| (RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update ceph-radosgw-14.2.11-181.el7cp.x86_64.rpm | Linux |
| (RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update ceph-radosgw-14.2.11-181.el8cp.x86_64.rpm | Linux |
| (RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update ceph-selinux-14.2.11-181.el7cp.x86_64.rpm | Linux |
| (RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update ceph-selinux-14.2.11-181.el8cp.x86_64.rpm | Linux |
| (RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update libcephfs-devel-14.2.11-181.el7cp.x86_64.rpm | Linux |
| (RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update libcephfs-devel-14.2.11-181.el8cp.x86_64.rpm | Linux |
| (RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update libcephfs2-14.2.11-181.el7cp.x86_64.rpm | Linux |
| (RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update libcephfs2-14.2.11-181.el8cp.x86_64.rpm | Linux |
| (RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update librados-devel-14.2.11-181.el7cp.x86_64.rpm | Linux |
| (RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update librados-devel-14.2.11-181.el8cp.x86_64.rpm | Linux |
| (RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update librados2-14.2.11-181.el7cp.x86_64.rpm | Linux |
| (RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update librados2-14.2.11-181.el8cp.x86_64.rpm | Linux |
| (RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update libradospp-devel-14.2.11-181.el7cp.x86_64.rpm | Linux |
| (RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update libradospp-devel-14.2.11-181.el8cp.x86_64.rpm | Linux |
| (RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update libradosstriper1-14.2.11-181.el7cp.x86_64.rpm | Linux |
| (RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update libradosstriper1-14.2.11-181.el8cp.x86_64.rpm | Linux |
| (RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update librbd-devel-14.2.11-181.el7cp.x86_64.rpm | Linux |
| (RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update librbd-devel-14.2.11-181.el8cp.x86_64.rpm | Linux |
| (RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update librbd1-14.2.11-181.el7cp.x86_64.rpm | Linux |
| (RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update librbd1-14.2.11-181.el8cp.x86_64.rpm | Linux |
| (RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update librgw-devel-14.2.11-181.el7cp.x86_64.rpm | Linux |
| (RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update librgw-devel-14.2.11-181.el8cp.x86_64.rpm | Linux |
| (RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update librgw2-14.2.11-181.el7cp.x86_64.rpm | Linux |
| (RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update librgw2-14.2.11-181.el8cp.x86_64.rpm | Linux |
| (RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update libtcmu-1.5.2-4.el7cp.x86_64.rpm | Linux |
| (RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update libtcmu-1.5.2-4.el8cp.x86_64.rpm | Linux |
| (RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update python-ceph-argparse-14.2.11-181.el7cp.x86_64.rpm | Linux |
| (RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update python-cephfs-14.2.11-181.el7cp.x86_64.rpm | Linux |
| (RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update python-rados-14.2.11-181.el7cp.x86_64.rpm | Linux |
| (RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update python-rbd-14.2.11-181.el7cp.x86_64.rpm | Linux |
| (RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update python-rgw-14.2.11-181.el7cp.x86_64.rpm | Linux |
| (RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update python3-ceph-argparse-14.2.11-181.el8cp.x86_64.rpm | Linux |
| (RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update python3-cephfs-14.2.11-181.el8cp.x86_64.rpm | Linux |
| (RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update python3-rados-14.2.11-181.el8cp.x86_64.rpm | Linux |
| (RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update python3-rbd-14.2.11-181.el8cp.x86_64.rpm | Linux |
| (RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update python3-rgw-14.2.11-181.el8cp.x86_64.rpm | Linux |
| (RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update rbd-mirror-14.2.11-181.el7cp.x86_64.rpm | Linux |
| (RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update rbd-mirror-14.2.11-181.el8cp.x86_64.rpm | Linux |
| (RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update rbd-nbd-14.2.11-181.el7cp.x86_64.rpm | Linux |
| (RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update rbd-nbd-14.2.11-181.el8cp.x86_64.rpm | Linux |
| (RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update tcmu-runner-1.5.2-4.el7cp.x86_64.rpm | Linux |
| (RHSA-2021:2445) Red Hat Ceph Storage 4.2 Security and Bug Fix Update tcmu-runner-1.5.2-4.el8cp.x86_64.rpm | Linux |
| distributed storage and file system (USN-4998-1) ceph_15.2.12-0ubuntu0.20.04.1_amd64.deb | Linux |
| distributed storage and file system (USN-4998-1) ceph_15.2.12-0ubuntu0.20.10.1_amd64.deb | Linux |
| distributed storage and file system (USN-4998-1) cephadm_15.2.12-0ubuntu0.20.04.1_amd64.deb | Linux |
| distributed storage and file system (USN-4998-1) cephadm_15.2.12-0ubuntu0.20.10.1_amd64.deb | Linux |
| distributed storage and file system (USN-4998-1) radosgw_15.2.12-0ubuntu0.20.04.1_amd64.deb | Linux |
| distributed storage and file system (USN-4998-1) radosgw_15.2.12-0ubuntu0.20.10.1_amd64.deb | Linux |
| distributed storage and file system (USN-4998-1) ceph-mgr_15.2.12-0ubuntu0.20.04.1_amd64.deb | Linux |
| distributed storage and file system (USN-4998-1) ceph-mgr_15.2.12-0ubuntu0.20.10.1_amd64.deb | Linux |
| distributed storage and file system (USN-4998-1) ceph-base_15.2.12-0ubuntu0.20.04.1_amd64.deb | Linux |
| distributed storage and file system (USN-4998-1) ceph-base_15.2.12-0ubuntu0.20.10.1_amd64.deb | Linux |
| distributed storage and file system (USN-4998-1) ceph-common_15.2.12-0ubuntu0.20.04.1_amd64.deb | Linux |
| distributed storage and file system (USN-4998-1) ceph-common_15.2.12-0ubuntu0.20.10.1_amd64.deb | Linux |
| distributed storage and file system (USN-4998-1) ceph-mgr-rook_15.2.12-0ubuntu0.20.04.1_all.deb | Linux |
| distributed storage and file system (USN-4998-1) ceph-mgr-rook_15.2.12-0ubuntu0.20.10.1_all.deb | Linux |
| distributed storage and file system (USN-4998-1) ceph-mgr-cephadm_15.2.12-0ubuntu0.20.04.1_all.deb | Linux |
| distributed storage and file system (USN-4998-1) ceph-mgr-cephadm_15.2.12-0ubuntu0.20.10.1_all.deb | Linux |
| distributed storage and file system (USN-4998-1) ceph-mgr-dashboard_15.2.12-0ubuntu0.20.04.1_all.deb | Linux |
| distributed storage and file system (USN-4998-1) ceph-mgr-dashboard_15.2.12-0ubuntu0.20.10.1_all.deb | Linux |
| distributed storage and file system (USN-4998-1) ceph-mgr-k8sevents_15.2.12-0ubuntu0.20.04.1_all.deb | Linux |
| distributed storage and file system (USN-4998-1) ceph-mgr-k8sevents_15.2.12-0ubuntu0.20.10.1_all.deb | Linux |
| distributed storage and file system (USN-4998-1) ceph-mgr-modules-core_15.2.12-0ubuntu0.20.04.1_all.deb | Linux |
| distributed storage and file system (USN-4998-1) ceph-mgr-modules-core_15.2.12-0ubuntu0.20.10.1_all.deb | Linux |
| distributed storage and file system (USN-4998-1) ceph-mgr-diskprediction-cloud_15.2.12-0ubuntu0.20.04.1_all.deb | Linux |
| distributed storage and file system (USN-4998-1) ceph-mgr-diskprediction-cloud_15.2.12-0ubuntu0.20.10.1_all.deb | Linux |
| distributed storage and file system (USN-4998-1) ceph-mgr-diskprediction-local_15.2.12-0ubuntu0.20.04.1_all.deb | Linux |
| distributed storage and file system (USN-4998-1) ceph-mgr-diskprediction-local_15.2.12-0ubuntu0.20.10.1_all.deb | Linux |
| distributed storage and file system (USN-5128-1) ceph_16.2.6-0ubuntu0.21.04.2_amd64.deb | Linux |
| distributed storage and file system (USN-5128-1) ceph_12.2.13-0ubuntu0.18.04.10_i386.deb | Linux |
| distributed storage and file system (USN-5128-1) ceph_12.2.13-0ubuntu0.18.04.10_amd64.deb | Linux |
| distributed storage and file system (USN-5128-1) ceph-base_16.2.6-0ubuntu0.21.04.2_amd64.deb | Linux |
| distributed storage and file system (USN-5128-1) ceph-base_12.2.13-0ubuntu0.18.04.10_i386.deb | Linux |
| distributed storage and file system (USN-5128-1) ceph-base_12.2.13-0ubuntu0.18.04.10_amd64.deb | Linux |
| distributed storage and file system (USN-5128-1) ceph-common_16.2.6-0ubuntu0.21.04.2_amd64.deb | Linux |
| distributed storage and file system (USN-5128-1) ceph-common_12.2.13-0ubuntu0.18.04.10_i386.deb | Linux |
| distributed storage and file system (USN-5128-1) ceph-common_12.2.13-0ubuntu0.18.04.10_amd64.deb | Linux |
| distributed storage and file system (USN-4998-1) cephadm_15.2.12-0ubuntu0.20.04.1_amd64.deb | Linux |
| distributed storage and file system (USN-4998-1) radosgw_15.2.12-0ubuntu0.20.04.1_amd64.deb | Linux |
| distributed storage and file system (USN-4998-1) ceph-mgr_15.2.12-0ubuntu0.20.04.1_amd64.deb | Linux |
| distributed storage and file system (USN-4998-1) ceph-mgr-rook_15.2.12-0ubuntu0.20.04.1_all.deb | Linux |
| distributed storage and file system (USN-4998-1) ceph-mgr-cephadm_15.2.12-0ubuntu0.20.04.1_all.deb | Linux |
| distributed storage and file system (USN-4998-1) ceph-mgr-dashboard_15.2.12-0ubuntu0.20.04.1_all.deb | Linux |
| distributed storage and file system (USN-4998-1) ceph-mgr-k8sevents_15.2.12-0ubuntu0.20.04.1_all.deb | Linux |
| distributed storage and file system (USN-4998-1) ceph-mgr-modules-core_15.2.12-0ubuntu0.20.04.1_all.deb | Linux |
| distributed storage and file system (USN-4998-1) ceph-mgr-diskprediction-cloud_15.2.12-0ubuntu0.20.04.1_all.deb | Linux |
| distributed storage and file system (USN-4998-1) ceph-mgr-diskprediction-local_15.2.12-0ubuntu0.20.04.1_all.deb | Linux |
Patch Details
No records foundReferences
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234