GPU VulnDB

Database/Control plane, storage & DevOps

Ceph MON (ceph-mon): The monitor accepts pool create/delete and snapshot operations from any authenticated user that

CVE-2018-10861Control plane, storage & DevOpscurated

Impact

The monitor accepts pool create/delete and snapshot operations from any authenticated user that only has read access. A read-only tenant key becomes a cluster-wide destructive capability - it can delete the pool holding another tenant's dataset or corrupt their RBD snapshots.

Who can reach it

Any authenticated Ceph user with read access that can reach the monitors, so any tenant node holding a client keyring.

What to do

Upgrade ceph-mon to the fixed release and restart it. Then review pool-level and mon caps for every client key, and separate tenants into distinct pools with explicit per-pool caps rather than a broad read cap.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.